Luke Taylor
|
27faad3402
SEC-1488: Remove commons-logging dependencies from maven poms and use slf4j in all samples.
|
15 years ago |
Luke Taylor
|
aaa7bd90b2
SEC-1481: Updated constructors of Authentication types to use a generic wildcard for authorities collection.
|
15 years ago |
Luke Taylor
|
295e0ded18
SEC-1483: Change User constructor to use a generic wildcard for authorities collection.
|
15 years ago |
Luke Taylor
|
304f12fb63
SEC-1455: Load namespace parsers when required, rather than on init() call, to avoid classloaded issue with dmServer failing to resolve web classes when the namespace handler is first used.
|
15 years ago |
Luke Taylor
|
8cbe232fbf
SEC-1480: Add simple equals and hashcode methods based on DN value to LdapUserDetailsImpl to allow its use as a map key (in SessionRegistry, for example).
|
15 years ago |
Luke Taylor
|
5ac106808e
Remove outdated scm information from pom.xml.
|
15 years ago |
Luke Taylor
|
8c605516b3
SEC-1463: Change namespace user-service parser to store username in lower-case when building map for in-memory UserDetailsService. Lookups are supposed to be case-insensitive with this class.
|
15 years ago |
Luke Taylor
|
e6e168f127
SEC-1456: Set rtexprvalue=true for "url" attribute in access tag to allow dynamic values (such as URL of current page).
|
15 years ago |
Luke Taylor
|
6d6c2d31ef
SEC-1462: Only apply session fixation protection strategy if request.isRequestedSessionIdValid() returns true. We don't need to create a new session if the current one already has a different Id from the client.
|
15 years ago |
Luke Taylor
|
8f6aecac9b
Clarify that multiple authentication-provider elements can be used in combination.
|
15 years ago |
Luke Taylor
|
0760bb947b
SEC-1458: Remove logger field in HttpSessionEventPublisher in favour of direct lookup. Prevents early initialization of logging system when listener is initialized.
|
15 years ago |
Luke Taylor
|
9d2e2ca11d
SEC-1232: Add config dependency to maven build for aspectj sample.
|
15 years ago |
Luke Taylor
|
6354c7e052
SEC-1232: GlobalMethodSecurityBeanDefinitionParser support for mode='aspectj'
|
15 years ago |
Luke Taylor
|
42cdaa0ce2
Latest gradle syntax updates.
|
15 years ago |
Luke Taylor
|
eda60b72b1
SEC-1448: Fixed failure to resolve generic method argument names in MethodSecurityEvaluationContext.
|
15 years ago |
Luke Taylor
|
0d198d42ae
SEC-1444: Fix JNDI escaping problems in LDAP authentication.
|
15 years ago |
Luke Taylor
|
f000aaa7e8
SEC-1440: Implement support for separate entry-point-ref on htt-basic namespace element. Changes ported from master branch.
|
15 years ago |
Luke Taylor
|
634e340d80
Update schema version to 3.0.3
|
15 years ago |
Luke Taylor
|
4c8e9e2d7e
SEC-1450: Replace use of ClassUtils.getMostSpecificMethod() in AbstractFallbackMethodDefinitionSource with AopUtils.getMostSpecificMethod() equivalent.
|
15 years ago |
Luke Taylor
|
e518adbef1
SEC-1443: Modify Jsr250Voter to handle multiple "RolesAllowed" roles.
|
15 years ago |
Luke Taylor
|
59b69f6f48
SEC-1434: Remove use of BeanDefinition of type java.lang.String which causes problems in Google App Engine.
|
15 years ago |
Luke Taylor
|
b8e50c0933
SEC-1439: Make getters and setters public on HttpRequestResponseHolder.
|
15 years ago |
Luke Taylor
|
677576ea8b
SEC-1429: Fix test. Wasn't setting allowSessionCreation=false on failure handler.
|
15 years ago |
Luke Taylor
|
91153df78d
SEC-1262: Added new (replacement) AspectJ interceptor which wraps the JoinPoint in a MethodInvocation adapter to provide compatibility with classes which only support MethodInvocation instances.
|
15 years ago |
Luke Taylor
|
1b0ac9c785
Porting of gradle changes from master.
|
15 years ago |
Luke Taylor
|
8c9159f273
Added repo for aws-maen 3.0.0 dep
|
15 years ago |
Luke Taylor
|
4c8b0faa88
Upgrade aws-maven to 3.0.0.RELEASE (mvn 2.2.x compatible)
|
15 years ago |
Luke Taylor
|
5a5b62e2cb
SEC-1429: Removed cached authentication from session after successful authentication.(cherry picked from commit 43f0e111067dec72f2a496ad7d9df9fc10de43dc)
|
15 years ago |
Luke Taylor
|
6ac8588144
Fix to Javadoc for AbstractAuthenticationProcessingFilter.(cherry picked from commit a3263753d93bba781471135448c4de5564fe464a)
|
15 years ago |
Luke Taylor
|
5690f1c581
SEC-1428: Check if response has been committed before redirecting to target URL in AbstractAuthenticationTargetUrlRequestHandler.
|
15 years ago |