Bez popisu

Luke Taylor 51a53ddbaa Minor refactoring of GAE code to use specific GrantedAuthority type. před 15 roky
acl 1c8d28501c SEC-1550: Convert signatures to use Collection<? extends GrantedAuthority> where appropriate. před 15 roky
aspects 21ed5feb8d SEC-1600: Added Implementation-Version and Implementation-Title to manifest templates and checking of version numbers in namespace config module and core. Config checks the version of core it is running against and core checks the Spring version, reporting any mismatches or situations where the app is running with less than the recommended Spring version. před 15 roky
buildSrc 37810a19c4 SEC-1619: Added check in GAE sample for change of Google user while still logged into the app. před 15 roky
cas 21ed5feb8d SEC-1600: Added Implementation-Version and Implementation-Title to manifest templates and checking of version numbers in namespace config module and core. Config checks the version of core it is running against and core checks the Spring version, reporting any mismatches or situations where the app is running with less than the recommended Spring version. před 15 roky
config b9a98613eb SEC-1593: Added tests to try to reproduce issue. před 15 roky
core 7754882ba9 SEC-1550: Additional signature change (in AnonymousAuthenticationToken) před 15 roky
docs 6b691f6fc0 SEC-1613: Corrected preauth docs. před 15 roky
gradle f85baac943 Updated to Spring 3.0.5 před 15 roky
itest 8d867e8b67 Updated integration tests to detect case reported as SPR-7563. před 15 roky
ldap 4b6a2168c7 SEC-1550: Additional signature change (in LdapUserDetailsManager.removeAuthorities()) před 15 roky
openid 265cdaf2a6 SEC-1595: Added extra constructor to OpenID4JavaConsumer which takes a ConsumerManager to allow a version compatible with GAE to be injected. před 15 roky
samples 51a53ddbaa Minor refactoring of GAE code to use specific GrantedAuthority type. před 15 roky
sandbox f4d57ab5e8 SEC-1456: Remove maven poms as we are now using gradle for the build. před 15 roky
taglibs 1c8d28501c SEC-1550: Convert signatures to use Collection<? extends GrantedAuthority> where appropriate. před 15 roky
web 60970dd9c4 Added some tests for web expression handling code. před 15 roky
.gitignore 7d97adc687 SEC-1584: Addition of HttpFirewall strategy to FilterChainProxy to reject un-normalized requests and wrap the incoming request object before processing by the security filter chain to provide a more consistent representation of paths than is guaranteed by the servlet spec. The wrapper strips path parameters from pathInfo and servletPath to provide consistency of URL matching across servlet containers and protect against bypassing security constraints by the malicious addition of such parameters to the URL. The paths are canonicalized further by replacing of multiple sequences of "/" characters with a single "/". před 15 roky
build.gradle 566328fea4 Minor tweaking of IDEA deps. před 15 roky
class_mapping_from_2.0.x.txt 48dcc211e9 SEC-1148: Simple classname mapping from 2.0 to 3.0 před 16 roky
gradlew c9b0bc1bd9 Added gradle wrapper support. před 15 roky
gradlew.bat c9b0bc1bd9 Added gradle wrapper support. před 15 roky
license.txt c3507b26c9 Change to Apache License version 2.0. před 21 roky
notice.txt 9cf146ecf1 Broaden list of names used and correct URL. před 18 roky
readme.txt 2c219f7a66 Bringing readme file up to date. před 15 roky
settings.gradle 58d9903ebc SEC-1564: JAAS Configuration can now be injected into DefaultJaasAuthenticationProvider před 15 roky

readme.txt

===============================================================================
SPRING SECURITY - README FILE
===============================================================================

-------------------------------------------------------------------------------
OVERVIEW
-------------------------------------------------------------------------------

Spring Security provides security services for the Spring Framework
(http://www.springframework.org). Spring Security 3.1 requires Spring 3.0.3 as
a minimum and also requires Java 5.

For a detailed list of features and access to the latest release, please visit
http://www.springframework.org/projects/.

Spring Security is released under an Apache 2.0 license. See the accompanying
license.txt file.

-------------------------------------------------------------------------------
BUILDING
-------------------------------------------------------------------------------

Please read the "Building from Source" page at
http://static.springframework.org/spring-security/site/.

-------------------------------------------------------------------------------
DOCUMENTATION
-------------------------------------------------------------------------------

Be sure to read the Reference Guide (docs/reference/html/springsecurity.html).
Extensive JavaDoc for the Spring Security code is also available (in docs/apidocs).
Both can also be found on the website.

-------------------------------------------------------------------------------
QUICK START
-------------------------------------------------------------------------------

We recommend you visit http://static.springframework.org/spring-security/site and
read the "Getting Started" page.

-------------------------------------------------------------------------------
MAVEN REPOSITORY DOWNLOADS
-------------------------------------------------------------------------------

Release jars for the project are available from the central maven repository

http://repo1.maven.org/maven2/org/springframework/security/

Note that milestone releases and snapshots are not uploaded to the central
repository, but can be obtained from the Spring milestone repository, using the
maven repository http://maven.springframework.org/snapshot/. You can't browse this
URL directly, but there is a separate browser interface. Check the downloads page
for more information
http://static.springsource.org/spring-security/site/downloads.html


-------------------------------------------------------------------------------
OBTAINING SUPPORT
-------------------------------------------------------------------------------

There are two types of support available, commercial and community. For
commercial support, please contact SpringSource. SpringSource employ the
people who wrote Spring Security, and lead the development of the project:

http://www.springsource.com

For peer help and assistance, please use the Spring Security forum
located at the Spring Community's forum site:

http://forum.springframework.org

Links to the forums, and other useful resources are
available from the web site.