7006 Commits

Author SHA1 Message Date
Josh Cummings
de640a10d6
Next Development Version 2018-07-26 16:02:51 -06:00
Josh Cummings
85c8d53b36
Release 5.0.7.RELEASE 5.0.7.RELEASE 2018-07-26 14:46:31 -06:00
Josh Cummings
2d6bcf2cc3
Update to Spring Data Kay SR8
Fixes: gh-5591
2018-07-26 14:43:54 -06:00
Josh Cummings
18b98fc607
Update to Spring Framework 5.0.8
Fixes: gh-5590
2018-07-26 14:42:39 -06:00
Joe Grandja
7bf8091e22 Update to hibernate-validator:6.0.11.Final
Fixes gh-5576
2018-07-24 17:26:17 -04:00
Joe Grandja
d19d03dea8 Update to bcpkix-jdk15on:1.60
Fixes gh-5574
2018-07-24 17:26:16 -04:00
Joe Grandja
35df3ff89b Update to org.apache.httpcomponents:httpclient:4.5.6
Fixes gh-5573
2018-07-24 17:26:16 -04:00
Joe Grandja
5f75e137d8 Update to ehcache:2.10.5
Fixes gh-5572
2018-07-24 17:26:16 -04:00
Joe Grandja
b988f656c6 Update to javax.servlet.jsp.jstl-api:1.2.2
Fixes gh-5571
2018-07-24 17:26:16 -04:00
Joe Grandja
06fff9441e Update to oauth2-oidc-sdk:5.64.2
Fixes gh-5569
2018-07-24 17:26:16 -04:00
Joe Grandja
edb354a2a9 Update to nimbus-jose-jwt:5.14
Fixes gh-5568
2018-07-24 17:26:16 -04:00
Joe Grandja
1ce0cf44a8 Update to cglib-nodep:3.2.7
Fixes gh-5567
2018-07-24 17:26:16 -04:00
Josh Cummings
ffd8f7c8e4 Close Nimbus Information Leak
This commit captures and remaps the exception that Nimbus throws
when a PlainJWT is presented to it.

While the surrounding classes are likely only used today by the
oauth2Login flow, since they are public, we'll patch them at this
point for anyone who may be using them directly.

Fixes: gh-5457
2018-07-24 13:24:34 -06:00
Rob Winch
ecaa2c5b1c Cache Control disabled for 304
Fixes: gh-5534
2018-07-17 22:13:52 -05:00
Rob Winch
a1c381c276 Add JdbcUserDetailsManager(DataSource) constructor
Fixes: gh-5512
2018-07-13 15:58:36 -05:00
mhyeon.lee
1b213d65d2 Enhance OAuth2AccessToken to be serializable
Change the TokenType to Serializable
so that the OAuth2AccessToken can be serialized.
(org.springframework.security.oauth2.core.OAuth2AccessToken.TokenType)

Fixes gh-5492
2018-07-13 12:10:55 -04:00
mhyeon.lee
eb897ac69c Fix oauth2login loginProcessingUrl NPE for java config
Java Config http.oauth2Login().loginProcessingUrl("url"); throws NPE.
Override loginProcessingUrl method and cached config url.
Then when the config is initialized,
it calls the super method to complete the configuration.

Fixes gh-5488
2018-07-13 11:42:43 -04:00
Rob Winch
bd8180da12 Update to Spring Boot 2.0.3.RELEASE
Issue: gh-5454
2018-06-20 15:53:56 -05:00
Rob Winch
5dabff25c3 Next Development Version 2018-06-12 21:24:07 -05:00
Rob Winch
09429479fe Release 5.0.6.RELEASE 5.0.6.RELEASE 2018-06-12 21:23:02 -05:00
Rob Winch
dc602c0840 Update to Spring Framework 5.0.7
Fixes: gh-5425
2018-06-12 16:51:01 -05:00
Rob Winch
fedc183b5b Fix htmlunit
Fixes: gh-5426
2018-06-12 16:50:52 -05:00
Rob Winch
d3f12f0ee7 Update to Selenium 3.12.0
Fixes: gh-5427
2018-06-12 16:50:48 -05:00
Rob Winch
2a723cf5c7 Update to htmlunit-driver:2.31.0
Fixes: gh-5428
2018-06-12 16:50:42 -05:00
Rob Winch
6f32303866 Update to hibernate-validator:6.0.10.Final
Fixes: gh-5429
2018-06-12 16:50:34 -05:00
Rob Winch
400adaef1c Update to Hibernate 5.2.17
Fixes: gh-5430
2018-06-12 16:50:29 -05:00
Rob Winch
9924d6e920 Update to hsqldb:2.4.1
Fixes: gh-5431
2018-06-12 16:50:23 -05:00
Rob Winch
6cfd30aee8 Update to assertj-core:3.10.0
Fixes: gh-5432
2018-06-12 16:50:15 -05:00
Rob Winch
1abdb69615 Update to htmlunit:2.31
Fixes: gh-5433
2018-06-12 16:49:23 -05:00
Rob Winch
b07f6b0178 Update to unboundid-ldapsdk:4.0.6
Fixes: gh-54234
2018-06-12 16:49:10 -05:00
Rob Winch
f0eec1b03b Update to oauth2-oidc-sdk:5.62
Fixes: gh-5435
2018-06-12 16:48:57 -05:00
Rob Winch
6ca6d80184 Update to nimbus-jose-jwt:5.11
Fixes: gh-5436
2018-06-12 16:47:35 -05:00
Rob Winch
ce5eec8761 Update to Jackson 2.9.6
Fixes: gh-5424
2018-06-12 16:47:30 -05:00
Rob Winch
86e03b3fb4 Update to Spring Boot 2.0.2.RELEASE
Fixes: gh-5423
2018-06-12 16:47:26 -05:00
Rob Winch
c909264b31 Update GAE to 1.9.64
Fixes: gh-5422
2018-06-12 16:47:21 -05:00
Rob Winch
f52ab9a146 Update to Reactor Bismuth SR10
Fixes: gh-5421
2018-06-12 16:47:06 -05:00
Rob Winch
ad2cb501b8 Add cross references to ReactorContextTestExecutionListener
Fixes: gh-5418
2018-06-11 17:16:15 -05:00
Rob Winch
8659a4b555 Add UserDetailsRepositoryReactiveAuthenticationManager.setScheduler
Fixes: gh-5417
2018-06-11 14:30:11 -05:00
Joe Grandja
e04b29426b DefaultLoginPageGeneratingFilter escapes OAuth2 ClientRegistrations
Fixes gh-5394
2018-05-29 09:53:31 -04:00
Josh Cummings
350d434e28
Next Development Version 2018-05-08 09:25:49 -06:00
Josh Cummings
bbfc3d2b4b
Release 5.0.5.RELEASE 5.0.5.RELEASE 2018-05-08 09:22:58 -06:00
Rob Winch
a7e4f36dbe Update to Spring Data Kay SR7
Fixes: gh-5318
2018-05-08 09:04:23 -05:00
Rob Winch
e61aafe115 Update to Reactor Bismuth SR9
Fixes: gh-5319
2018-05-08 09:04:05 -05:00
Rob Winch
ff95388ce1 Update to Spring 5.0.6
Fixes: gh-5290
2018-05-08 08:34:35 -05:00
Rob Winch
545228cf8d Documentation typo fixes
Fixes: gh-5317
2018-05-07 16:48:03 -05:00
Denys Ivano
7b8fa90d96 Add accessDeniedHandler method to ExceptionHandlingSpec
This allows to configure accessDeniedHandler in ExceptionTranslationWebFilter through ServerHttpSecurity.

Issue: gh-5257
2018-05-07 16:23:32 -05:00
Alexander Münch
c30e218f1f Avoid unnecessary grow of ArrayList
Adapted ArrayList size in CacheControlHeadersWriter::createHeaders()

Fixes: gh-5310
2018-05-04 14:43:17 -05:00
XYUU
70d284865f DefaultLoginPageGeneratingFilter should calculate ContentLength using UTF-8
Fixes: gh-5309
2018-05-04 14:43:17 -05:00
Johnny Lim
a4b5523063 Fix 'attributes' deprecation warning in spring-security-docs-guides
Fixes: gh-5308
2018-05-04 14:13:44 -05:00
Kazuki Shimizu
8883ec17e5 Fix JdbcDaoImpl Javadoc
Fix incorrect explanation for customizing query on JdbcDaoImpl

Issue: gh-5306
2018-05-04 10:48:55 -05:00