Spring Security Add container-based testing to CI

In light of https://github.com/spring-projects/spring-security/issues/13794, we should consider adding tests to Spring S...

Spring Security Cannot create a session after the response has been committed

Describe the bugAfter upgrading an app to Spring Boot 3, a working filter chain that works in the latest Spring Boot 2 v...

Spring Security Add logging to CsrfTokenRequestHandler implementations

Comment From: andreilisaHello @jzheaux, I would like to work on it if it is actual, but I will need some details.What in...

Spring Security The solution to configure PortMapper for oauth2Login() breaks authorization code grant flow due to missing registration of DefaultLoginPageGeneratingFilter

Describe the bug12307 is now closed. So I created this issue.In this comment it suggests to use this to configure PortMa...

Spring Security org.springframework.security.web.authentication.ui.DefaultLoginPageGeneratingFilter doesn't work while ${spring.mvc.servlet.path} property is not '/'

Describe the bugorg.springframework.security.web.authentication.ui.DefaultLoginPageGeneratingFilter doesn't work while $...

Spring Security RefreshTokenOAuth2AuthorizedClientProvider does not handle expired refresh token

SummaryRefresh tokens don't support timeouts - if refresh token expires application will keep trying to refresh access t...

Spring Security Pattern Spring Security after Spring Data/Cloud

Based on conversations and my own experiences getting into Spring Ecosystem, Spring Security stands as a large obstacle ...

Spring Security Incorrect link in the documentation

Expected BehaviorThe link associated with Spring Security’s Filters instances in the AuthenticationManager section of th...

Spring Security Documentation enhancement for Custom Pointcuts

In current the documentation for Matching Methods with Custom Pointcuts there are examples of custom pointcut in Java/Ko...

Spring Security Bump Gradle Wrapper from 8.4 to 8.5

Forward port of #14218Comment From: marcusdacoregioClosed via https://github.com/spring-projects/spring-security/commit/...

Spring Security ReactiveAuthorizationManager + Reactive Method Security

We should provide an implementation of Reactive Method Security that leverages ReactiveAuthorizationManager similar to g...

Spring Security Prepare for Spring Security 6.2

Update SecurityNamespaceHandler to require 6.2Add spring-security-6.2.rnc and spring-security-6.2.xsdUpdate spring.schem...

Spring Security OAuth2RestTemplate deprecated from spring boot 3

Question SummaryIf applicable, please mention:Environment: Cloud FoundryAdditional informationI want to migrate a applic...

Spring Security Spring security 6 / OAuth2 authentication with custom provider fails because of "=" (%3D) padding mismatch.

Describe the bugA normally successful (using Postman) OAuth2 authentication using a WordPress OAuth2 plugin as a custom ...

Spring Security SecurityMockMvcRequestPostProcessors.csrf() doesn't work with XorCsrfTokenRequestAttributeHandler

Describe the bugUsing SecurityMockMvcRequestPostProcessors.csrf() gives invalid CSRF token when configuration contains c...

Spring Security Set default redirect in OidcClientInitiatedServerLogoutSuccessHandler

SummaryI ❤️ the new OidcClientInitiatedServerLogoutSuccessHandler in Spring Security 5.2! The only problem I see with it...

Spring Security OIDC Backchannel Logout Handler Endpoint 404

I have configured OIDC backchannel logout in an application with a context-path. Issuing the logout from the provider d...

Spring Security Make OIDC Back-Channel Logout API Public

In #12570, it was decided to make the OIDC Back-Channel Logout API private for now to allow the feature to be released a...

Spring Security Consider adding common scenario/pattern based security configurations

Spring security has a massive number of configuration options and it can be quite overwhelming to know which combination...

Spring Security spring.security counters inaccurate due onComplete and cancel()

Describe the bugSome spring.security counters contain still wrong value after active counter were fixed#14031At least th...
上一页 下一页
.