Luke Taylor
|
f536c80020
SEC-1202: Removed SpringSecurityFilter and replaced with use of GenericFilterBean from spring-web
|
vor 16 Jahren |
Luke Taylor
|
b807f7cbdd
Added comment to pom to explain spring-web requirement
|
vor 16 Jahren |
Luke Taylor
|
972cd0a53c
javadoc
|
vor 16 Jahren |
Luke Taylor
|
d65b1b3581
SEC-1200: Ukranian messages file
|
vor 16 Jahren |
Luke Taylor
|
966f3e4101
SEC-1182: Added tst to confirm that this is no longer an issue due to other changes
|
vor 16 Jahren |
Luke Taylor
|
b4bb489638
SEC-1164: Further registering on bean components for tooling and removal of global ids.
|
vor 16 Jahren |
Luke Taylor
|
b387d63aba
Removing unnecessary global bean names.
|
vor 16 Jahren |
Luke Taylor
|
a67448c867
SEC-1216: Remove unused code.
|
vor 16 Jahren |
Luke Taylor
|
229866e293
SEC-1142: Support for session timeout detection. Added namespace support for invalid-session-url
|
vor 16 Jahren |
Luke Taylor
|
c12e5b4d0b
SEC-1142: Renamed setter argument to match property.
|
vor 16 Jahren |
Luke Taylor
|
ea73fd0130
SEC-1142: Simplified implementation by removing template method.
|
vor 16 Jahren |
Luke Taylor
|
90d76373cc
SEC-1142: Support for session timeout detection. Added redirect to invalidSessionUrl in SessionManagementFilter when an invalid session Id is supplied in the request.
|
vor 16 Jahren |
Luke Taylor
|
0f6642d3ab
SEC-1216: Replacement of custom-after-invocation-provider with after-invocation-provider element. Some changes to help prevent proxying of aop infrastructure classes (use of AopInfrastructureBean marker interface)
|
vor 16 Jahren |
Luke Taylor
|
eaa0dc4fce
typo
|
vor 16 Jahren |
Luke Taylor
|
e40b9fbc75
SEC-1196: Introduce AuthenticationManagerDelegator is MethodSecurityInterceptor which is configured by global-method-security. Prevents regression of SEC-933 caused by eager init of AuthenitcationManager and dependent beans
|
vor 16 Jahren |
Luke Taylor
|
997faabe1e
SEC-1196: Removed ConfigUtils (no longer used).
|
vor 16 Jahren |
Luke Taylor
|
5953af0f6b
SEC-1196: Change use of <authentication-manager> to actually register the global ProviderManager instance. This element now registers the global ProviderManager instance and must contain any authentication-provider elements (or ldap-authentication-provider elements).
|
vor 16 Jahren |
Luke Taylor
|
c5d6484b54
SEC-1210: RememberMe filter misses UserDetailsService in default <http /> tag config when it is declared in parent app context. Fixed by getting the UserDetailsServiceInjectionPostProcessor to check ancestor bean factories for a UserDetailsService if one isn't found in the current bean factory.
|
vor 16 Jahren |
Luke Taylor
|
160aa512a1
Remove "infrastructure" type from authentication provider bean.
|
vor 16 Jahren |
Luke Taylor
|
6ae61f95db
Minor updates to test XML context implementation.
|
vor 16 Jahren |
Luke Taylor
|
a4a0aab66f
SEC-1164: Add additional component definitions so that Spring IDE picks them up and doesn;t report missing bean definitions
|
vor 16 Jahren |
Luke Taylor
|
06e393a171
Update bundlor to M5
|
vor 16 Jahren |
Luke Taylor
|
ecbacddc7c
SEC-1146: Add some information on using authority groups
|
vor 16 Jahren |
Luke Taylor
|
5d5df0c63d
Added extra 'manual' security interceptor config
|
vor 16 Jahren |
Luke Taylor
|
68364f06a2
Minor itest updates
|
vor 16 Jahren |
Luke Taylor
|
3e6054b69f
SEC-1211: Rename SessionFixationProtectionFilter to SessionManagementFilter, since it no longer performs session-fixation protection directly, but just executes the AuthenticatedSessionStrategy.
|
vor 16 Jahren |
Luke Taylor
|
5e285b3692
SEC-1211: Set the default AuthenticatedSessionStrategy to a null implementation to preserve existing behaviour.
|
vor 16 Jahren |
Luke Taylor
|
609a68b12a
SEC-1077: Added DefaultAuthenticatedSessionStrategy test to check that saved request attribute is retained when migrateAttributes is false.
|
vor 16 Jahren |
Luke Taylor
|
db90122179
SEC-1211: Create strategy for session handling on successful authentication. Added AuthenticatedSessionStrategy interface and default implementation which encapsulates the functionality that was previously in SessionFixationProtectionFilter and AbstractAuthentictationProcessingFilter. Updated the namespace to make use of these.
|
vor 16 Jahren |
Luke Taylor
|
4a12b80470
Minor updates to x509 doc and update of remember-me doc (no longer part of auto-config)
|
vor 16 Jahren |