Spring Security WebInvocationPrivilegeEvaluator does not provide a way to pass a ServletContext

Describe the bugSee https://github.com/spring-projects/spring-boot/issues/27728 for background.When using the following ...

Spring Security Update io.spring.javaformat to 0.0.29

Comment From: spring-projects-issuesFixed via fafde0910f8e5f4b38f1efcd8d479031fb88103bComment From: sjohnrReverted via f...

Spring Security Syntactially wrong Javadoc for AbstractRequestMatcherRegistry

Describe the bughttps://github.com/spring-projects/spring-security/blob/6db58cbf8a26296a15eb9f9c187176f099acaa77/config/...

Spring Security Allow Defining Custom SAML 2.0 Assertion Signature Validator

Related #10263 Comment From: marcusdacoregioClosing this because when discussing with the team there is no need to make ...

Spring Security Deprecate RemoteAuthenticationManager and RemoteAuthenticationProvider

Related #10361We should deprecate classes in org.springframework.security.authentication.rcp in spring-security-core sin...

Spring Security x5t:base64encodedthumbprint and typ:JWT missing in generated client_assertion

Describe the bugI use Spring Boot 2.5.0 where Spring Security 5.5.0 is included.From issue https://github.com/spring-pro...

Spring Security Client JwtBearer grant type should allow to build Jwt based on the client registration information

Expected BehaviorAs per RFC7521 and 7523, there is some claims that compose the Jwt that are related to the client regis...

Spring Security Client JwtBearer grant type should not require a Jwt when already authorized

Expected BehaviorBeing able to provide JwtAuthenticationToken only when required.Current BehaviorIn the actual requireme...

Spring Security Warning "Set of valid issuers was not available" when using OpenSAML 4.1.1

Expected BehaviorValidation of a valid SAML response should not produce a warningCurrent BehaviorValidation of a valid S...

Spring Security Allow creating OIDC id token decoder outside of OidcIdTokenDecoderFactory

Expected BehaviorAllow creating OIDC id token decoder outside of OidcIdTokenDecoderFactory without regrading the registr...

Spring Security Use Antora

SummaryWe should consider using https://antora.org for creating the documentation

Spring Security Update to Spring Boot 2.4.11

Update to Spring Boot 2.4.11Comment From: spring-projects-issuesFixed via 397781e57c8bfa5d0dc28bb153b04a91d0dd3ba5

Spring Security Deprecate EhCache2 support

Since Spring Framework moved from EhCache to JSR 107 support, we should do the sameSee:- https://github.com/spring-proje...

Spring Security SAML: Add RequestedAuthnContext to AuthnRequest in OpenSamlAuthenticationRequestFactory

SummaryAdd RequestedAuthnContext with Comparison and AuthnContextClassRef to require a certain authentication from the I...

Spring Security getClaimAsBoolean should not be falsy

Related to https://github.com/spring-projects/spring-security/issues/10117#issuecomment-883638049ClaimAccessor#getClaimA...

Spring Security Documentation : Spring security architecture guide describes old auto configuration from Spring Boot 1.x

Spring security architecture guide needs to be changed to reflect the simplification done to the security auto configura...

Spring Security Add saml2.ValidIssuers parameter into SAML 2.0 Assertion Validators

Related #10263 Add the saml2.ValidIssuers parameter into the assertionValidator and assertionSignatureValidator to preve...

Spring Security Update to oauth2-oidc-sdk:6.18.1

Comment From: nor-ek@jzheaux Hi, as I can see there is currently com.nimbusds:oauth2-oidc-sdk:9.15 in spring-security-de...

Spring Security please support lazily doing issuer checks (and all other checks) on startup for oauth resource servers

right now the app is slowed a bit by HTTP checks it has to make when the app startsup. other implementations do a lot of...

Spring Security DefaultBearerTokenResolver triggers processing of multipart content

Affected Artifact: <groupId>org.springframework.security</groupId> <artifactId>spring-securi...
上一页 下一页
.