Commit History

Author SHA1 Message Date
  Ben Alex 35ca25f085 BasicAuthenticationProcessingFilter no longer creates HttpSession via WebAuthenticationDetails call. 20 years ago
  Ben Alex 55f5c3397a Relocated JdbcDaoExtendedImpl.convertAclObjectIdentityToString to superclass (pursuant to suggestion made by Tim Kettering on acegisecurity-developer). 20 years ago
  Ben Alex e805aa2e73 Add annotation support. 20 years ago
  Mark St. Godard ec5e39c2e8 Initial checkin of user security context switching (see SEC-15). This is the first cut of the SwitchUserProcessingFilter that handles switching to a target uesr and exiting back to the original user. Note: This is going to be used for the common use-case of an Administrator 'switching' to another user (i.e. ROLE_ADMIN -> ROLE_USER). This is the initial cut of a Unix 'su' for Acegi managed web applications. 20 years ago
  Scott McCrory c2c48b905b Added package.html files to reamining java packages (see http://opensource.atlassian.com/projects/spring/browse/SEC-41) 20 years ago
  Scott McCrory f4c8211cc2 Replaced .cvsignore placeholders for package.html files (which also serve some doccumentary purpose). 20 years ago
  Scott McCrory db4ed4bc44 Added debug statement to AbstractTicketValidator to help with Acegi+CAS+SSL setup (thanks Seth Ladd for the patch) (see http://opensource.atlassian.com/projects/spring/browse/SEC-34) 20 years ago
  Scott McCrory c66c5dfab5 AuthorizeTag no longer depends on JDK 1.4. Tested on Websphere 5.0 w/JDK 1.3 (see http://opensource.atlassian.com/projects/spring/browse/SEC-11) 20 years ago
  Ben Alex f20bc6d9d0 Catch up with recent changes. 20 years ago
  Ben Alex f650289142 Avoid expense of HttpSession when working with anonymous users. 20 years ago
  Ben Alex c8275c591f Reflect additional releases made for backporting SEC-20 security fix. 20 years ago
  Ben Alex 3e4a29eae9 FilterSecurityInterceptor now has an observeOncePerRequest boolean property, allowing multiple fragments of the HTTP request to be individually authorized (see http://opensource.atlassian.com/projects/spring/browse/SEC-14). 20 years ago
  Ben Alex d09d250656 Form, CAS, X509 and Remember-Me authentication mechanisms now publish an InteractiveAuthenticationSuccessEvent (see http://opensource.atlassian.com/projects/spring/browse/SEC-5). 20 years ago
  Ben Alex 60f8095cf2 Make Authenticated.isAuthenticated() behaviour switchable. See http://opensource.atlassian.com/projects/spring/browse/SEC-13. 20 years ago
  Ben Alex ef8281f534 HttpSessionContextIntegrationFilter elegantly handles IOExceptions and ServletExceptions within filter chain (see http://opensource.atlassian.com/projects/spring/browse/SEC-20). 20 years ago
  Ben Alex a3d26edea3 JBoss container adapter to use getName() instead to toString() (see http://opensource.atlassian.com/projects/spring/browse/SEC-22). 20 years ago
  Ben Alex a312fede74 Refactor DAO authentication failure events under a consistent abstract superclass (thanks to Mark St Godard for suggestion). 20 years ago
  Ben Alex c0f1d4e19d Remove getters and setters from JdbcDaoImpl so IoC container cannot modify MappingSqlQuerys (thanks to David Durham for bug report). 20 years ago
  Ben Alex a15691d9d7 Silently catch NotSerializableException in AbstractProcessingFilter if rootCause is not Serializable (thanks to Joseph Dane for reporting this bug). 20 years ago
  Ben Alex 5f75e9bf9a Refactor Authentication.isAuthenticated() handling to be more performance (as per developer list discussion). 20 years ago
  Ben Alex a7b5299e77 Correct synchronization issue with FilterToBeanProxy initialization (thanks to George Franciscus and Volker Malzahn as per acegisecurity-developer discussion 4 June 2005). 20 years ago
  Ben Alex c699f7d40e Support non-username as primary key. 20 years ago
  Ben Alex 4e55780e7c Performance optimisations thanks to Paulo Neves. 20 years ago
  Ben Alex cfb8271826 Reorder DaoAuthenticationProvider exception logic as per developer list discussion. 20 years ago
  Ben Alex ecbfac2ff8 Made AclEntry Serializable (correct issue with BasicAclEntryCache). 20 years ago
  Ben Alex e08e66dec6 Refactor SecurityContextHolder to return a SecurityContext instead of Authentication. 20 years ago
  Ben Alex 6a9abe5d90 Remove ContextHolder and introduce SecurityContext. 20 years ago
  Luke Taylor d4da559ccc added entry for credential expiry modifications 20 years ago
  Ben Alex d169829f27 AbstractAuthenticationToken.getName() now returns username alone if UserDetails present. 20 years ago
  Ray Krueger 6f286e2054 AuthorityGranter.grant now returns a java.util.Set of role names, instead of a single role name 20 years ago