Spring Security After adding custom filters, permitAll() does not work

SummaryAfter adding custom JWT filter for authentication, all paths with permitAll() are still passing through the custo...

Spring Security Add Jackson Support for Objects stored in HttpSession

It would be nice to provide custom serialization mechanism that uses Jackson for objects Spring Security places in sessi...

Spring Security When browser language is 'Korean', can't see korean debug message

Describe the bugWhen browser language is 'Korean', can't see korean debug messageTo ReproduceWhen browser language is Ko...

Spring Security Add securityContext to Kotlin DSL

The Kotlin DSL should allow customizing the SecurityContext management.This functionality already exists on the Java DSL...

Spring Security AuthorizationManagerWebInvocationPrivilegeEvaluator does not provide access to ServletContext

Describe the bugWhen using Spring-Boot 2.6.4 + Spring-Security usage of an ApplicationContextRequestMatcher (such as End...

Spring Security Trigger CI from release automation

Currently, a git push from release-next-version.yml does not trigger the CI process (GitHub seems to suppress it to avoi...

Spring Security Inject AuthenticationManager fail with Dubbo

Repository Versionspring-boot 2.3.7.RELEASEspring-cloud-alibaba 2.2.2.RELEASEspring-security-config 5.3.6.RELEASEspring-...

Spring Security OAuth2 Not redirecting to referring page when using login endpoint

Describe the bugWhen OAuth2 is configured, and in particular, when multiple OAuth2 endpoints are defined or in combinati...

Spring Security Fix setServletContext not being called for AuthorizationManagerWebInvocationPrivilegeEvaluator

Backport of #11165 Comment From: marcusdacoregioFixed via https://github.com/spring-projects/spring-security/commit/9d37...

Spring Security Fix setServletContext not being called for AuthorizationManagerWebInvocationPrivilegeEvaluator

Related - #10908 Comment From: marcusdacoregioFixed via https://github.com/spring-projects/spring-security/commit/23594b...

Spring Security Allow overriding the web client resolver used for ReactiveJwtDecoders.fromIssuerLocation()

For non-reactive applications just settingsecurity.oauth2.resourceserver.jwt.issuer-uri: http://some.non.public.host/som...

Spring Security Enhancement request - Spring Security to remove support for EOL OpenSAML 3

Hello Spring Security Team,I just wanted to open this enhancement request. Please kindly consider it if you can.Currentl...

Spring Security generateChangelog task should not include duplicate issues

The generateChangelog task which is used to create the release notes on the release page is including issues labeled as ...

Spring Security Documentation has only an XML namespace introduction to eraseCredentialsAfterAuthentication

Expected BehaviorIn Spring Security 5.6.2, the process of configuring AuthenticationManagerBuilder.eraseCredentials(fals...

Spring Security Authorization on Every Dispatch Type

Currently FilterSecurityInterceptor and AuthorizationFilter only perform authorization checks on the first request. Auth...

Spring Security Update spring-ldap-core to 2.3.7.RELEASE

Comment From: marcusdacoregioClosed via https://github.com/spring-projects/spring-security/commit/6724627b50dac2d53f2086...

Spring Security Update org.springframework.data to 2021.1.3

Comment From: marcusdacoregioClosed via https://github.com/spring-projects/spring-security/commit/4aab7b06a9a06d861e1a9d...

Spring Security Update org.springframework to 5.3.19

Comment From: marcusdacoregioClosed via https://github.com/spring-projects/spring-security/commit/d0d4d58c48313696c3a12e...

Spring Security Update hibernate-entitymanager to 5.6.8.Final

Comment From: marcusdacoregioClosed via https://github.com/spring-projects/spring-security/commit/29be60d0359344b7063152...

Spring Security Update org.eclipse.jetty to 9.4.46.v20220331

Comment From: marcusdacoregioClosed via https://github.com/spring-projects/spring-security/commit/5024103b0722b539cdc1bf...
上一页 下一页
.