Luke Taylor
|
8ce4d326f5
Update HttpClient to 4.1.2 and removed incorrect bundlor references to commons version.
|
14 lat temu |
Luke Taylor
|
0120643721
SEC-1794: Convert OpenIDAuthenticationStatus to an enum.
|
14 lat temu |
Luke Taylor
|
0c2a950fa0
SEC-1788: Avoid unnecessary call to getPreAuthenticatedPrincipal() in AbstractPreAuthenticatedProcessingFilter when not checking for principal changes is not enabled.
|
14 lat temu |
Rob Winch
|
7399c9a7a5
SEC-1792: Fixed NullPointerException in RunAsUserToken#toString()
|
14 lat temu |
Rob Winch
|
dfd467f26e
cleaned imports in RunAsUserToken
|
14 lat temu |
Luke Taylor
|
7e44580c75
Minor refactoring of aspects tests.
|
14 lat temu |
Luke Taylor
|
8740efc0f5
Added constructor injection options to ConcurrentSessionFilter
|
14 lat temu |
Luke Taylor
|
a1c714cff4
SEC-1754: Added an InvalidSessionStrategy to allow SessionManagementFilter to delegate out the behaviour when an invalid session identifier is submitted.
|
14 lat temu |
Luke Taylor
|
ac3d8b25f2
Expand LDAP authentication FAQ with information about bind authentication and unreadable password attributes.
|
14 lat temu |
Luke Taylor
|
8440743108
Remove Sql query objects from JdbcTokenRepositoryImpl in favour of direct JdbcTemplate use.
|
14 lat temu |
Luke Taylor
|
89fa771093
SEC-1753: Cater for missing DiscoveryInformation object in OpenID4JavaConsumer.endConsumption.
|
14 lat temu |
Luke Taylor
|
700fa9e0b6
SEC-1772: remote URL decoding of targetUrlParameter in AbstractAuthenticationTargetUrlRequestHandler.
|
14 lat temu |
Luke Taylor
|
de97bac85b
SEC-1763: Prevent nested switches in SwitchUserFilter by calling attemptExitUser() before doing the switch.
|
14 lat temu |
Luke Taylor
|
a504cfae1a
SEC-1770: Call refreshLastRequest on the session registry rather than the SessionInformation object to make sure it works with alternative SessionRegistry implementations.
|
14 lat temu |
Luke Taylor
|
d5946b81b4
Added FAQ on how to add ApacheDS entries to pom.
|
14 lat temu |
Luke Taylor
|
c117c643df
SEC-1782: Javadoc correction for LdapAuthenticationProvider.
|
14 lat temu |
Rob Winch
|
330f82f562
SEC-1777: Corrected log in HttpSessionSecurityContextRepository to reference itself instead of HttpSessionContextIntegrationFilter
|
14 lat temu |
Florian Fankhauser
|
2e83d98c8f
SEC-1776: Corrected typo in manual
|
14 lat temu |
Rob Winch
|
825f0061fb
SEC-1761: Support HttpOnly Flag for Cookies when using Servlet 3.0
|
14 lat temu |
Luke Taylor
|
56e86dd36f
Adding assertions on constructor arg values.
|
14 lat temu |
Luke Taylor
|
f92589f051
Extract a SecurityFilterChain interface and create a default implementation to facilitate other configuration options.
|
14 lat temu |
Luke Taylor
|
2d271666a4
Add constructors to facilitate constructor-based injection for required/shared bean properties.
|
14 lat temu |
Luke Taylor
|
73442125de
SEC-1775: Removed internal use of UserAttribute class in AnonymousAuthenticationFilter.
|
14 lat temu |
Luke Taylor
|
5d20f57fa8
Import cleaning.
|
14 lat temu |
Luke Taylor
|
b15475ab3d
SEC-1771: Change TokenBasedRememberMeServices to obtain password from UserDetailsService if necessary.
|
14 lat temu |
Luke Taylor
|
737a9d1825
Improved toString methods on request wrappers.
|
14 lat temu |
Rob Winch
|
85807fdfd0
Removed @Overrides from method that implements interface instead of overriding superclass to resolve Java 1.5 error
|
14 lat temu |
Rob Winch
|
c3a3a5bfbf
Updated core.gradle to include crypto as referenced project in eclipse
|
14 lat temu |
Luke Taylor
|
d253f5e109
SEC-1768: Use AopProxyUtils.ultimateTargetClass() to cater for the situation where the security interceptor is being applied to a proxy.
|
14 lat temu |
Luke Taylor
|
5a1ddc660b
SEC-1768: Added tests to reproduce "double-proxying" issue combining intercept-methods and tx-annotation-driven. Problem is caused by use of ProxyFactoryBean with auto-proxying.
|
14 lat temu |