Spring Security LogoutConfigurer#createLogoutFilter sets the SecurityContextHolderStrategy twice

The org.springframework.security.config.annotation.web.configurers.LogoutConfigurer#createLogoutFilter method sets the S...

Spring Security SAML: RelyingPartyRegistration only allows a single ACS binding/location

Expected BehaviorRelyingPartyRegistration should allow multiple ACS binding/location combinations (e.g., POST, REDIRECT,...

Spring Security Allow custom strategy for ActiveDirectoryLdapAuthenticationProvider.searchForUser

Please provide customization of variable 'searchControls' inside ActiveDirectoryLdapAuthenticationProvider.searchForUser...

Spring Security FilterChainProxy issue with Spring Boot 3.2.2

Describe the bugWe are updating our Spring Boot 3.1.5 project to 3.2.2And we are getting this issue with FilterChainProx...

Spring Security Application context fails to load: Couldn't find FilterChainProxy

Describe the bugApplication context fails to load after upgrading from spring boot version 3.1.5 to 3.2.1 with error mes...

Spring Security Fix Package Tangle in CAS

Betweenorg.springframework.security.cas.authentication.CasAuthenticationProvider andorg.springframework.security.cas.web...

Spring Security Fix Package Tangle in SAML 2.0

Betweenorg.springframework.security.saml2.provider.service.metadata.RequestMatcherMetadataResponseResolver andorg.spring...

Spring Security Structure101 Plugin Should Ignore Deprecated Files

If a package tangle is due to a deprecated file, it should be ignored. This facilities repairing package tangles after G...

Spring Security Build is not failing when Structure 101 reports an error

Comment From: jzheauxWhen running Structure101 locally:16-Feb-2024 17:39:44,838 [main] WARN - FAIL! fatPackage has incr...

Spring Security Deprecation of AbstractSecurityInterceptor

The deprecation note advises to use technology-specific interceptor (web, messaging or method), but AbstractSecurityInte...

Spring Security supported SAML response types

Describe the bugSAML Response (IdP -> SP)There are 8 examples:An unsigned SAML Response with an unsigned AssertionAn ...

Spring Security Use alternate (internal) URL for OIDC configuration during ISS claim validation

The problemWe currently facing a very special problem using Spring Security OAuth in conjunction with Keycloak in a cont...

Spring Security How can I add dynamic permission rules?

when I configure the HttpSecurity like this:When the server is running,and I can't restart it.The server need keep runni...

Spring Security I found the bug of remember me.

My project uses the remember function. When I first enter the account password, the access is normal. When I close the b...

Spring Security Enable support for persistent sessions when using SessionRegistryImpl

SummaryWhen you use spring-boot with devTools you get persistent servlet session out-of-the-box that is preserved across...

Spring Security Improve OAuth2 docs landing page

As a follow up to gh-13784, we should improve the OAuth2 docs page to include:Code examples:[x] Kotlin examples[ ] XML e...

Spring Security Authentication Features

This issue is a theme for the Spring Security 6.2 release. Issues that relate to this will be added below.SAML 2.0[ ] :s...

Spring Security Configuration Improvements

This issue is a theme for the Spring Security 6.2 release. Issues that relate to this will be added below.Configuration ...

Spring Security Compatibility with JVM snapshots (OpenJDK's Project CRaC)

As a project wide initiative the portfolio is looking into support for Project CRaC which allows JVM snapshots to be tak...

Spring Security IntelliJ built-in Gradle runner cannot run tests

When attempting to run tests on the 5.7.x branch using the built-in Gradle runner, the tests fail to compile and reporti...
上一页 下一页
.