Spring Security Build Automation

This issue is an ongoing theme for the Spring Security. Issues that relate to this will be added below.Build Improvement...

Spring Security Research whether dependabot is capable of upgrading our dependencies

Some notes here:Dependabot supports ignoring major, minor, or patch updatesgradle-dependency-submission project support...

Spring Security No HTTP Session Created for SP Initaited SLO

I am currently on Saml2-Service-Provider 5.8.9 and I am in the process of implementing a SP Initated SLO.To initiated th...

Spring Security Support sending SAML 2.0 LogoutRequest to the IdP (Single Logout)

Expected BehaviorIt would be nice to be able to send a samlp:LogoutRequest to the SAML Identity Provider, to trigger a S...

Spring Security Add support for nested property names in oauth2.providers.userNameAttribute

Expected BehaviorI was trying to configure my app to use the pagerduty oauth2 provider, I was using the following config...

Spring Security Spring Security 6 - Webflux Custom AuthenticationWebFilter not triggering

Describe the bugI am trying to build an application which performs a check against an API Key for a subset of endpoints....

Spring Security Support Certificate-Bound (POP) JWT Access Token Validation (Reactive)

This issue is for the Reactive implementation of gh-10538.Comment From: franticticktickHi @jgrandja! What specific suppo...

Spring Security Add DelegatingServerLogoutSuccessHandler

Need to add DelegatingServerLogoutSuccessHandler, that iterates over multiple ServerLogoutSuccessHandler. This implement...

Spring Security Cannot override cache for Nimbus(Reactive)JwtDecoder in (Reactive)OidcIdTokenDecoderFactory

Expected BehaviorIt should be possible to customize cache in NimbusJwtDecoder created by OidcIdTokenDecoderFactory.Nimbu...

Spring Security Update to Bouncycastle 1.78

Backgroundspring-security-rsa 1.1.2Compile dependency bcprov-jdk18on 1.77 has a recently published CVE.Please upgrade de...

Spring Security SEC-1767: Allow to change Authentication Failure Handler in security namespace for SessionManagementFilter

Roberto Ruiz (Migrated from SEC-1767) said:In form login, I use a custom Authentication failure handler to redirect to l...

Spring Security Make OidcUserService overrideable

Expected BehaviorI would like to extend OidcUserService and override certain methods e.g. shouldRetrieveUserInfoCurrent ...

Spring Security Saml SSO configuration yaml file referenced in the docs not working properly with newer versions of spring boot

I was using the spring security docs and this link as a reference to implement SSO: https://medium.com/digital-software-...

Spring Security ReactiveOAuth2AuthorizedClientManagerConfiguration has been created too early

The Boot team is seeing the following warnings when running Spring Security related tests:2024-04-12T12:07:39.300+01:00 ...

Spring Security Update Documentation about Kotlin Coroutine Support

Based one this comment from @rrrship, the documentation should be updated to correctly state that Spring Security fully ...

Spring Security OpenSAML dependency is resolved from a 3rd party repository

As of #10556, support for OpenSAML 3 has been removed.Spring Boot is currently upgrading to Spring Security SNAPSHOTs an...

Spring Security Encoded password does not look like BCrypt with inmemoryAuthentication

When I am using inmemory authentication using BCryptPassword encoder, Authentication is failing and the logs states that...

Spring Security Support Certificate-Bound (POP) JWT Access Token Validation

https://datatracker.ietf.org/doc/html/draft-ietf-oauth-pop-architecture-08https://tools.ietf.org/id/draft-ietf-oauth-pop...

Spring Security Adding Signature to Service Provider Metadata in Spring Security SAML

I'm currently working with Spring Security SAML to generate service provider metadata for integration with an identity p...

Spring Security Endless Authentication Loop with ActiveDirectoryLdapAuthenticationProvider on Incorrect Password

Describe the bugEncountering an endless Authentication loop with Spring Security version 6.2.2 when incorrect LDAP crede...
上一页 下一页
.