Spring Security Configure the landing page after SSO authentication

SummaryI want to know how to setup the relay state with the new saml library. Basically once I am authenticated via the ...

Spring Security Whitespace target param handling in determineTargetUrl of AbstractAuthenticationTargetUrlRequestHandler

Under below condition, the method ignoresthis.useReferer. I wonder if it is done on purpose.- isAlwaysUseDefaultTargetUr...

Spring Security Relax final method implementations on AbstractRememberMeServices

Expected BehaviorAbstractRememberMeServices implemented RememberMeServices methods with final modifier. This actually bl...

Spring Security Consider adding a wiki page linking to the Migration Guide

Comment From: marcusdacoregiohttps://github.com/spring-projects/spring-security/wiki/Spring-Security-6.0-Migration-Guide

Spring Security JwtAuthenticationProvider should use provided authentication details

Describe the bugJwtAuthenticationProvider delegates the instantiation of an Authentication to a Converter<Jwt, ? exte...

Spring Security @EnableReactiveMethodSecurity#useAuthorizationManager should be true

Describe the bugIn the documentation to migrating a reactive application to spring security 6.0.0 is an issue (or the im...

Spring Security CsrfRequestDataValueProcessor uses a different attribute name then the rest of the CSRF parts.

When working with Spring Webflux and CSRF protection additional steps are needed to expose the CSRF Token to the fronten...

Spring Security create a distribution zip gradle task like the spring framework project

Expected Behaviordevelopers can build all of modules with its jar .source and api doc to a zip fileCurrent Beha...

Spring Security ClientRegistrations should only accept application/json MediaType

Expected BehaviorAs mentionned in OpenID documentation, Open ID Provider Configuration should only provide application/j...

Spring Security Align SessionManagementDsl with SessionManagementConfigurer

Expected BehaviorKotlin's SessionManagementDsl should have all the configurable properties that the SessionManagementCon...

Spring Security Spring security ignores loginPage and loginProcessingUrl update when there is a custom UsernamePasswordAuthenticationFilter

Describe the bugI am using spring security httpBasic and formLogin with rememberMe functionality. My goal was to replace...

Spring Security {baseUrl} does not return the proper path if the server is behind the reverse proxy

If a server is behind a reverse proxy, for example, the application correct URL is "https://www.exmaple.com/t1/app-conte...

Spring Security Analyze causes of StackOverflowError using AuthenticationManager bean

There are a lot of reports about a StackOverflowError when exposing the AuthenticationManager as a bean and using it ins...

Spring Security Set unique values for docsearch version_rank

Right now the latest version is ranked highest, but we could improve this so that other versions are ranked properly too...

Spring Security Make Authentication/SecurityContext Immutable

SummaryNOTE: This was originally brought up as a question in gh-8322 this ticket is to resolve that questionIdeally we w...

Spring Security AuthorizationManager support should be in authorization package

WebExpressionAuthorizationManager, ExpressionAuthorizationDecision, and DefaultHttpSecurityExpressionhandler are in org....

Spring Security Wrong name of the filter in the SecurityContextHolderFilter diagram

Hi,diagram related to SecurityContextHolderFilter is referring to SecurityContextPersistenceFilter instead of SecurityCo...

Spring Security SessionDestroyedEvent not getting triggered under certain conditions

We currently have class SessionDestroyedListener implements ApplicationListener<SessionDestroyedEvent> defined whi...

Spring Security Security observations are not setting their parent osbervation

Original issue: spring-projects/spring-boot#33495Spring Boot auto-configures the reactive ServerHttpObservationFilter ah...

Spring Security Feature-branch build should fail if its main-branch Antora configuration is missing

When a feature branch is added, like 5.8.x, it currently needs to be added to the antora-playbook.yml and local-antora-p...
上一页 下一页
.