Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							9b4cbff58c 
							
						 
					 
					
						
						
							
							SEC-2782: Additional Updates to Migration Guide from 3.x to 4.x  
						
						
						
						
					 
					
						2015-03-06 17:10:06 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							ff4e9e6ad4 
							
						 
					 
					
						
						
							
							SEC-2782: Started Migration Guide from 3.x to 4.x  
						
						
						
						
					 
					
						2015-02-27 16:18:18 -06:00 
						 
				 
			
				
					
						
							
							
								drdamour 
							
						 
					 
					
						
						
						
						
							
						
						
							ff5a176675 
							
						 
					 
					
						
						
							
							trivial docs fixed a few typos and grammatical errors  
						
						... 
						
						
						
						I have signed and agree to the terms of the SpringSource Individual Contributor License Agreement. 
						
						
					 
					
						2015-02-25 00:04:15 -06:00 
						 
				 
			
				
					
						
							
							
								Eugene Wolfson 
							
						 
					 
					
						
						
						
						
							
						
						
							4ca99ef88c 
							
						 
					 
					
						
						
							
							SEC-2877: Fix doc typo in index.adoc  
						
						... 
						
						
						
						Replace "a`" with "a `" 
						
						
					 
					
						2015-02-24 22:28:07 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							5f57e5b0c3 
							
						 
					 
					
						
						
							
							SEC-2873: Remember Me XML Configuration Defaults Should Match Java Config  
						
						
						
						
					 
					
						2015-02-24 20:49:56 -06:00 
						 
				 
			
				
					
						
							
							
								Kazuki Shimizu 
							
						 
					 
					
						
						
						
						
							
						
						
							67cd8465c3 
							
						 
					 
					
						
						
							
							SEC-2826: Add remember-me-cookie attribute in xml namespace  
						
						
						
						
					 
					
						2015-02-24 17:54:54 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							9ffd5db466 
							
						 
					 
					
						
						
							
							SEC-2584: Add What's New in 4.0  
						
						
						
						
					 
					
						2015-02-24 16:14:15 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							bfa12ade40 
							
						 
					 
					
						
						
							
							SEC-2870: Add Spring Data Documentation  
						
						
						
						
					 
					
						2015-02-24 16:14:08 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							37740cd020 
							
						 
					 
					
						
						
							
							SEC-2861: Add WebSocket Documentation & Sample  
						
						
						
						
					 
					
						2015-02-24 10:29:47 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							b9563f6102 
							
						 
					 
					
						
						
							
							SEC-2830: Cleanup disabling Same Origin SockJS  
						
						... 
						
						
						
						- Defaults for properties false
- Add XML Namespace support 
						
						
					 
					
						2015-02-24 10:28:33 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							b9e2a57131 
							
						 
					 
					
						
						
							
							SEC-2854: Add intercept-message@message-type  
						
						
						
						
					 
					
						2015-02-20 11:43:16 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							fea03536d6 
							
						 
					 
					
						
						
							
							SEC-2853: Rename WebSocket XML Namespace elements  
						
						
						
						
					 
					
						2015-02-20 11:43:15 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							6a8475adbb 
							
						 
					 
					
						
						
							
							SEC-2830: Provide Same Origin support for SockJS  
						
						
						
						
					 
					
						2015-02-18 11:21:02 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							a27c33754c 
							
						 
					 
					
						
						
							
							SEC-2859: Add CsrfTokenArgumentResolver  
						
						
						
						
					 
					
						2015-02-18 10:51:30 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							c4fe630f8e 
							
						 
					 
					
						
						
							
							SEC-2846: Security HTTP Response Headers Configuration Cleanup  
						
						
						
						
					 
					
						2015-02-10 10:36:00 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							6627f76df7 
							
						 
					 
					
						
						
							
							SEC-2758: Make ROLE_ consistent  
						
						
						
						
					 
					
						2015-01-29 17:08:43 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							081f84844c 
							
						 
					 
					
						
						
							
							SEC-2777: Fix <header> attributes in doc  
						
						
						
						
					 
					
						2015-01-20 16:28:02 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							c30c97005b 
							
						 
					 
					
						
						
							
							SEC-2572: Document Spring Test  
						
						
						
						
					 
					
						2015-01-20 16:20:14 -06:00 
						 
				 
			
				
					
						
							
							
								Christopher Pelloux 
							
						 
					 
					
						
						
						
						
							
						
						
							aab0eea9cf 
							
						 
					 
					
						
						
							
							SEC-2800 Documentation typo in class name  
						
						
						
						
					 
					
						2014-12-22 19:22:26 -05:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							1677836d53 
							
						 
					 
					
						
						
							
							SEC-2790: Deprecate @EnableWebMvcConfig  
						
						
						
						
					 
					
						2014-12-10 21:10:27 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							3171cc4364 
							
						 
					 
					
						
						
							
							SEC-2788: Add @Configuration as meta annotation to @Enable* annotations  
						
						
						
						
					 
					
						2014-12-10 21:10:15 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							c67ff42b8a 
							
						 
					 
					
						
						
							
							SEC-2783: XML Configuration Defaults Should Match JavaConfig  
						
						... 
						
						
						
						* j_username -> username
* j_password -> password
* j_spring_security_check -> login
* j_spring_cas_security_check -> login/cas
* j_spring_cas_security_proxyreceptor -> login/cas/proxyreceptor
* j_spring_openid_security_login -> login/openid
* j_spring_security_switch_user -> login/impersonate
* j_spring_security_exit_user -> logout/impersonate
* login_error -> error
* use-expressions=true by default 
						
						
					 
					
						2014-12-08 15:09:15 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							87a52ffbfd 
							
						 
					 
					
						
						
							
							SEC-2784: Update to Gradle 2.2.1  
						
						
						
						
					 
					
						2014-12-08 13:29:07 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							6e204fff72 
							
						 
					 
					
						
						
							
							SEC-2781: Remove deprecations  
						
						
						
						
					 
					
						2014-12-04 15:28:40 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							2cb2657f5b 
							
						 
					 
					
						
						
							
							SEC-2702: Clean WebSocket Namespace documentation  
						
						
						
						
					 
					
						2014-11-25 12:27:29 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							3c487c0348 
							
						 
					 
					
						
						
							
							SEC-2348: Update doc headers enabled by default with XML  
						
						
						
						
					 
					
						2014-11-21 21:55:03 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							4392205f63 
							
						 
					 
					
						
						
							
							SEC-2347: CSRF Enabled by default w/ XML Config  
						
						
						
						
					 
					
						2014-11-21 21:32:56 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							eedbf44235 
							
						 
					 
					
						
						
							
							SEC-2348: Security HTTP Response Headers enabled by default w/ XML  
						
						
						
						
					 
					
						2014-11-21 16:06:29 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							4dcc89fab0 
							
						 
					 
					
						
						
							
							SEC-2674: Documentation refers to httpStrictTransportSecurity() instead of hsts()  
						
						
						
						
					 
					
						2014-11-19 13:31:09 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							55d6d5a86a 
							
						 
					 
					
						
						
							
							SEC-2615: accesscontrollist tag hasPermission performs OR not AND  
						
						... 
						
						
						
						In 3.1 the accesscontrollist tag began performing an and on the
permissions. This may have been accidental, but I think that it is more
intuitive & secure for it to behave this way. When compared to hasAnyRole
and hasRoles the hasPermission tag implies it is an and. If users end up
needing OR support, then the authorize tag can be used along with the
hasPermission expression. For example:
  <sec:authorize access="hasPermission(#domain, 'read') or hasPermission(#domain, 'write') ">
In general, the authorize tag should be preferred as it is the more
powerful way of performing authorization checks. 
						
						
					 
					
						2014-11-18 16:59:46 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							e7edb77cae 
							
						 
					 
					
						
						
							
							SEC-2716: Fix doc spelling of AbstractPreAuthenticatedProcessingFilter  
						
						
						
						
					 
					
						2014-09-16 10:56:52 -05:00 
						 
				 
			
				
					
						
							
							
								Bloshchetsov Andrey Evgenyevich 
							
						 
					 
					
						
						
						
						
							
						
						
							bd322542ca 
							
						 
					 
					
						
						
							
							Fixed broken url to Clickjacking description.  
						
						
						
						
					 
					
						2014-08-20 10:11:21 +04:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							934937d9c1 
							
						 
					 
					
						
						
							
							SEC-2688: CAS Proxy Ticket Authentication uses Service for host & port  
						
						
						
						
					 
					
						2014-08-15 16:41:33 -05:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							b97b84063a 
							
						 
					 
					
						
						
							
							SEC-2665: Fix samples/ldap-jc link in reference  
						
						
						
						
					 
					
						2014-07-21 14:20:14 -05:00 
						 
				 
			
				
					
						
							
							
								Alexander Grüneberg 
							
						 
					 
					
						
						
						
						
							
						
						
							d9efd08bfd 
							
						 
					 
					
						
						
							
							SEC-2577: Add missing whitespace in reference  
						
						
						
						
					 
					
						2014-04-28 16:24:48 -05:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							5b216bd0b2 
							
						 
					 
					
						
						
							
							Revert "SEC-2547: Consistent CAS client version"  
						
						... 
						
						
						
						This reverts commit f6cc9d87d5d85d8ea4c01696cbcd6f88ff558dca. 
						
						
					 
					
						2014-04-15 10:36:37 -05:00 
						 
				 
			
				
					
						
							
							
								Hans-Joachim Kliemeck 
							
						 
					 
					
						
						
						
						
							
						
						
							f6cc9d87d5 
							
						 
					 
					
						
						
							
							SEC-2547: Consistent CAS client version  
						
						
						
						
					 
					
						2014-04-14 22:48:55 -05:00 
						 
				 
			
				
					
						
							
							
								Luke Taylor 
							
						 
					 
					
						
						
						
						
							
						
						
							71ba977dad 
							
						 
					 
					
						
						
							
							Fix package name in manual code  
						
						
						
						
					 
					
						2014-03-27 13:08:23 +00:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							32d3e29c65 
							
						 
					 
					
						
						
							
							SEC-2325: Polish CSRF Tag support  
						
						... 
						
						
						
						- Rename csrfField to csrfInput
- Make AbstractCsrfTag package scope
- rename FormFieldTag to CsrfInputTag
- rename MetaTagsTag to CsrfMetaTagsTag
- removed whitespace from tag output so output is
  minimized & improving browser performance
- Update @since
- changed test names to be more meaningful 
						
						
					 
					
						2014-03-07 15:28:52 -06:00 
						 
				 
			
				
					
						
							
							
								beamerblvd 
							
						 
					 
					
						
						
						
						
							
						
						
							a3e0475998 
							
						 
					 
					
						
						
							
							SEC-2325 Added JSP tags for CSRF meta tags and form fields  
						
						
						
						
					 
					
						2014-03-07 15:28:48 -06:00 
						 
				 
			
				
					
						
							
							
								beamerblvd 
							
						 
					 
					
						
						
						
						
							
						
						
							26cee61b98 
							
						 
					 
					
						
						
							
							SEC-2335 Added ACL schema files for MySQL, SQL Server, Oracle  
						
						
						
						
					 
					
						2014-03-07 15:28:45 -06:00 
						 
				 
			
				
					
						
							
							
								Manimaran Selvan 
							
						 
					 
					
						
						
						
						
							
						
						
							1d6536fa71 
							
						 
					 
					
						
						
							
							SEC-2512: Fix typo in reference`  
						
						... 
						
						
						
						udates -> updates 
						
						
					 
					
						2014-03-06 22:22:34 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							4a1a2dfed4 
							
						 
					 
					
						
						
							
							Update min Spring version of 4.0.2.REELASE  
						
						
						
						
					 
					
						2014-02-19 11:16:57 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							6c35c33abe 
							
						 
					 
					
						
						
							
							SEC-2447: Fix AuthenticationManagerBuilder ordering issues  
						
						
						
						
					 
					
						2014-02-09 21:17:51 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							b5f5665ea6 
							
						 
					 
					
						
						
							
							SEC-2463: CSRF documentation includes EnableWebMvcSecurity  
						
						
						
						
					 
					
						2014-01-29 09:28:51 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							3b05fd6fed 
							
						 
					 
					
						
						
							
							SEC-2466: Add link to MultipartFilter in CSRF multipart section  
						
						
						
						
					 
					
						2014-01-28 22:04:35 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							4c84805ac9 
							
						 
					 
					
						
						
							
							SEC-2466: CSRF MutipartFilter doc now uses <url-pattern>  
						
						
						
						
					 
					
						2014-01-28 16:51:05 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							f09ce267b3 
							
						 
					 
					
						
						
							
							Polish MVC doc  
						
						
						
						
					 
					
						2013-12-16 12:30:25 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							5205bf57c6 
							
						 
					 
					
						
						
							
							SEC-2453: Create 403 CSRF FAQ Entry  
						
						
						
						
					 
					
						2013-12-16 09:02:02 -06:00 
						 
				 
			
				
					
						
							
							
								Rob Winch 
							
						 
					 
					
						
						
						
						
							
						
						
							0d12397662 
							
						 
					 
					
						
						
							
							SEC-2385: Polish Gradle Spring 4 usage doc  
						
						
						
						
					 
					
						2013-12-12 08:20:37 -06:00