| 
					
				 | 
			
			
				@@ -388,7 +388,7 @@ Below you can find the highlights of this release. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/pull/3938[#3938] - Add <<request-matching,HTTP response splitting prevention>> 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/issues/3949[#3949] - Add <<mvc-authentication-principal,bean reference support to @AuthenticationPrincipal>>. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/pull/3978[#3978] - Support for Standford WebAuth and Shibboleth using the newly added http://docs.spring.io/spring-security/site/docs/4.2.x-SNAPSHOT/apidocs/org/springframework/security/web/authentication/preauth/RequestAttributeAuthenticationFilter.html[RequestAttributeAuthenticationFilter]. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				-https://github.com/spring-projects/spring-security/issues/4076[#4076] - Document <<appendix-proxy-server,Proxy Server>> Configuration 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				+* https://github.com/spring-projects/spring-security/issues/4076[#4076] - Document <<appendix-proxy-server,Proxy Server>> Configuration 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/issues/3795[#3795] - `ConcurrentSessionFilter` supports `InvalidSessionStrategy` 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/pull/3904[#3904] - Add `CompositeLogoutHandler` 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				  
			 | 
		
	
	
		
			
				| 
					
				 | 
			
			
				@@ -397,7 +397,7 @@ https://github.com/spring-projects/spring-security/issues/4076[#4076] - Document 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/pull/3956[#3956] - Central configuration of the http://docs.spring.io/spring-security/site/migrate/current/3-to-4/html5/migrate-3-to-4-jc.html#m3to4-role-prefixing[default role prefix]. See the issue for details. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/issues/4102[#4102] - Custom default configuration in `WebSecurityConfigurerAdapter`. See <<jc-custom-dsls>> 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/issues/3899[#3899] - <<nsa-concurrency-control-max-sessions,concurrency-control@max-sessions>> supports unlimited sessions. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				-* https://github.com/spring-projects/spring-security/issues/3899[#4097] - <<nsa-intercept-url-request-matcher-ref,intercept-url@request-matcher-ref>> adds more powerful request matching support to the XML namespace. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				+* https://github.com/spring-projects/spring-security/issues/4097[#4097] - <<nsa-intercept-url-request-matcher-ref,intercept-url@request-matcher-ref>> adds more powerful request matching support to the XML namespace. 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/issues/3990[#3990] - Support for constructing `RoleHierarchy` from `Map` (i.e. `yml`) 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/pull/4062[#4062] - Custom cookiePath to `CookieCsrfTokenRepository` 
			 | 
		
	
		
			
				 | 
				 | 
			
			
				 * https://github.com/spring-projects/spring-security/issues/3794[#3794] - Allow configuration of `InvalidSessionStrategy` on `SessionManagementConfigurer` 
			 |