Commit History

Autor SHA1 Mensaxe Data
  Ben Alex f5741962ed Add createSessionAllowed property, which should be set to false to avoid unnecessary session creation. %!s(int64=20) %!d(string=hai) anos
  Ben Alex 35ca25f085 BasicAuthenticationProcessingFilter no longer creates HttpSession via WebAuthenticationDetails call. %!s(int64=20) %!d(string=hai) anos
  Ben Alex 55f5c3397a Relocated JdbcDaoExtendedImpl.convertAclObjectIdentityToString to superclass (pursuant to suggestion made by Tim Kettering on acegisecurity-developer). %!s(int64=20) %!d(string=hai) anos
  Ben Alex e805aa2e73 Add annotation support. %!s(int64=20) %!d(string=hai) anos
  Mark St. Godard ec5e39c2e8 Initial checkin of user security context switching (see SEC-15). This is the first cut of the SwitchUserProcessingFilter that handles switching to a target uesr and exiting back to the original user. Note: This is going to be used for the common use-case of an Administrator 'switching' to another user (i.e. ROLE_ADMIN -> ROLE_USER). This is the initial cut of a Unix 'su' for Acegi managed web applications. %!s(int64=20) %!d(string=hai) anos
  Scott McCrory c2c48b905b Added package.html files to reamining java packages (see http://opensource.atlassian.com/projects/spring/browse/SEC-41) %!s(int64=20) %!d(string=hai) anos
  Scott McCrory f4c8211cc2 Replaced .cvsignore placeholders for package.html files (which also serve some doccumentary purpose). %!s(int64=20) %!d(string=hai) anos
  Scott McCrory db4ed4bc44 Added debug statement to AbstractTicketValidator to help with Acegi+CAS+SSL setup (thanks Seth Ladd for the patch) (see http://opensource.atlassian.com/projects/spring/browse/SEC-34) %!s(int64=20) %!d(string=hai) anos
  Scott McCrory c66c5dfab5 AuthorizeTag no longer depends on JDK 1.4. Tested on Websphere 5.0 w/JDK 1.3 (see http://opensource.atlassian.com/projects/spring/browse/SEC-11) %!s(int64=20) %!d(string=hai) anos
  Ben Alex f20bc6d9d0 Catch up with recent changes. %!s(int64=20) %!d(string=hai) anos
  Ben Alex f650289142 Avoid expense of HttpSession when working with anonymous users. %!s(int64=20) %!d(string=hai) anos
  Ben Alex c8275c591f Reflect additional releases made for backporting SEC-20 security fix. %!s(int64=20) %!d(string=hai) anos
  Ben Alex 3e4a29eae9 FilterSecurityInterceptor now has an observeOncePerRequest boolean property, allowing multiple fragments of the HTTP request to be individually authorized (see http://opensource.atlassian.com/projects/spring/browse/SEC-14). %!s(int64=20) %!d(string=hai) anos
  Ben Alex d09d250656 Form, CAS, X509 and Remember-Me authentication mechanisms now publish an InteractiveAuthenticationSuccessEvent (see http://opensource.atlassian.com/projects/spring/browse/SEC-5). %!s(int64=20) %!d(string=hai) anos
  Ben Alex 60f8095cf2 Make Authenticated.isAuthenticated() behaviour switchable. See http://opensource.atlassian.com/projects/spring/browse/SEC-13. %!s(int64=20) %!d(string=hai) anos
  Ben Alex ef8281f534 HttpSessionContextIntegrationFilter elegantly handles IOExceptions and ServletExceptions within filter chain (see http://opensource.atlassian.com/projects/spring/browse/SEC-20). %!s(int64=20) %!d(string=hai) anos
  Ben Alex a3d26edea3 JBoss container adapter to use getName() instead to toString() (see http://opensource.atlassian.com/projects/spring/browse/SEC-22). %!s(int64=20) %!d(string=hai) anos
  Ben Alex a312fede74 Refactor DAO authentication failure events under a consistent abstract superclass (thanks to Mark St Godard for suggestion). %!s(int64=20) %!d(string=hai) anos
  Ben Alex c0f1d4e19d Remove getters and setters from JdbcDaoImpl so IoC container cannot modify MappingSqlQuerys (thanks to David Durham for bug report). %!s(int64=20) %!d(string=hai) anos
  Ben Alex a15691d9d7 Silently catch NotSerializableException in AbstractProcessingFilter if rootCause is not Serializable (thanks to Joseph Dane for reporting this bug). %!s(int64=20) %!d(string=hai) anos
  Ben Alex 5f75e9bf9a Refactor Authentication.isAuthenticated() handling to be more performance (as per developer list discussion). %!s(int64=20) %!d(string=hai) anos
  Ben Alex a7b5299e77 Correct synchronization issue with FilterToBeanProxy initialization (thanks to George Franciscus and Volker Malzahn as per acegisecurity-developer discussion 4 June 2005). %!s(int64=20) %!d(string=hai) anos
  Ben Alex c699f7d40e Support non-username as primary key. %!s(int64=20) %!d(string=hai) anos
  Ben Alex 4e55780e7c Performance optimisations thanks to Paulo Neves. %!s(int64=20) %!d(string=hai) anos
  Ben Alex cfb8271826 Reorder DaoAuthenticationProvider exception logic as per developer list discussion. %!s(int64=20) %!d(string=hai) anos
  Ben Alex ecbfac2ff8 Made AclEntry Serializable (correct issue with BasicAclEntryCache). %!s(int64=20) %!d(string=hai) anos
  Ben Alex e08e66dec6 Refactor SecurityContextHolder to return a SecurityContext instead of Authentication. %!s(int64=20) %!d(string=hai) anos
  Ben Alex 6a9abe5d90 Remove ContextHolder and introduce SecurityContext. %!s(int64=20) %!d(string=hai) anos
  Luke Taylor d4da559ccc added entry for credential expiry modifications %!s(int64=20) %!d(string=hai) anos
  Ben Alex d169829f27 AbstractAuthenticationToken.getName() now returns username alone if UserDetails present. %!s(int64=20) %!d(string=hai) anos