Spring Security
Go to file
Josh Cummings 64542b4059
Polish X509 SecurityContextRepository
Like Basic and Bearer authentication, X509 is
stateless by default. As such, it is better to not
pick up the global SecurityContextRepository bean.

The better fix is to change the default from
HttpSessionSecurityContextRepository to
RequestAttributeSecurityContextRepository.

Issue gh-13008
2023-04-18 12:18:20 -06:00
.github Merge branch '5.8.x' into 6.0.x 2023-02-01 15:25:47 -07:00
.idea Fix checkstyle rules could not be parsed 2020-11-23 14:33:18 -05:00
acl Merge branch '5.8.x' 2022-08-23 16:03:50 -05:00
aspects Merge remote-tracking branch 'origin/5.8.x' 2022-09-20 16:11:16 -06:00
bom fix bom 2021-05-17 22:29:45 -05:00
buildSrc Update io.projectreactor to 2022.0.6 2023-04-14 14:24:19 -03:00
config Polish X509 SecurityContextRepository 2023-04-18 12:18:20 -06:00
core Merge branch '5.8.x' into 6.0.x 2023-04-14 13:32:10 -03:00
crypto Avoid exception if PBKDF2WithHmacSHA256 is not available 2023-04-04 09:33:12 -03:00
data Use SecurityContextHolderStrategy for Data 2022-06-27 16:36:13 -06:00
dependencies Update spring-ldap-core to 3.0.2 2023-04-14 14:27:33 -03:00
docs Merge branch '5.8.x' into 6.0.x 2023-04-17 07:29:42 -03:00
etc Merge branch '5.8.x' into 6.0.x 2023-02-28 16:53:33 -06:00
git/hooks Use 6.0.x instead of 3.0.x as default branch 2022-08-24 16:38:27 -05:00
gradle/wrapper Merge branch '5.8.x' 2022-11-08 13:29:36 -03:00
itest use-authorization-manager defaults to true 2022-10-06 08:12:46 -06:00
ldap Merge branch '5.8.x' into 6.0.x 2022-12-15 15:53:00 -06:00
messaging Read Extracted Variables 2023-03-23 09:57:31 -06:00
oauth2 Merge branch '5.8.x' into 6.0.x 2023-04-12 12:46:11 -06:00
rsocket Adjust OAuth2 Resource Server packaging 2022-09-23 16:31:21 -06:00
saml2/saml2-service-provider Merge branch '5.8.x' into 6.0.x 2023-04-14 13:32:10 -03:00
scripts Exclude duplicate issues from changelog 2022-04-20 09:03:57 -03:00
taglibs Use SecurityContextHolderStrategy for Taglibs 2022-06-27 17:48:30 -06:00
test Merge branch '5.8.x' into 6.0.x 2023-04-14 13:32:10 -03:00
web Merge branch '5.8.x' into 6.0.x 2023-04-17 07:29:42 -03:00
.editorconfig Fixed link in .editorconfig 2021-10-13 15:36:10 -06:00
.gitattributes Install Structure101 Plugin 2021-09-27 14:56:03 -06:00
.gitignore Ignore Lock Files 2020-02-07 13:59:05 -06:00
.sdkmanrc Update java version to 17.0.3-tem 2022-06-14 14:43:34 -05:00
CONTRIBUTING.adoc Add rncToXsd task description to CONTRIBUTING.adoc 2022-10-03 10:09:27 -03:00
LICENSE.txt Add LICENSE.txt 2020-04-15 16:44:13 -05:00
README.adoc Merge branch '5.8.x' into 6.0.x 2023-03-20 16:59:52 -06:00
RELEASE.adoc Add automated release info to release doc 2022-08-16 11:46:04 -05:00
build.gradle Update io.spring.nohttp to 0.0.11 2023-02-17 14:53:21 -03:00
class_mapping_from_2.0.x.txt SEC-1148: Simple classname mapping from 2.0 to 3.0 2009-12-02 22:44:30 +00:00
gradle.properties Next development version 2023-04-17 16:17:33 +00:00
gradlew Update to Gradle 7.3 2021-11-10 11:05:18 -03:00
gradlew.bat Update to Gradle 6.6.1 2020-10-12 17:41:16 -06:00
notice.txt URL Cleanup 2019-03-19 23:53:23 -05:00
settings.gradle Update Gradle Enterprise plugin to 3.11.1 2022-09-16 13:14:53 -03:00

README.adoc

image::https://badges.gitter.im/Join%20Chat.svg[Gitter,link=https://gitter.im/spring-projects/spring-security?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge&utm_content=badge]

image:https://github.com/spring-projects/spring-security/workflows/CI/badge.svg?branch=main["Build Status", link="https://github.com/spring-projects/spring-security/actions?query=workflow%3ACI"]

image:https://img.shields.io/badge/Revved%20up%20by-Gradle%20Enterprise-06A0CE?logo=Gradle&labelColor=02303A["Revved up by Gradle Enterprise", link="https://ge.spring.io/scans?search.rootProjectNames=spring-security"]

= Spring Security

Spring Security provides security services for the https://docs.spring.io[Spring IO Platform]. Spring Security 6.0 requires Spring 6.0 as
a minimum and also requires Java 17.

For a detailed list of features and access to the latest release, please visit https://spring.io/projects[Spring projects].

== Code of Conduct
Please see our https://github.com/spring-projects/.github/blob/main/CODE_OF_CONDUCT.md[code of conduct]

== Downloading Artifacts
See https://docs.spring.io/spring-security/site/docs/current/reference/html5/#getting[Getting Spring Security] for how to obtain Spring Security.

== Documentation
Be sure to read the https://docs.spring.io/spring-security/site/docs/current/reference/htmlsingle/[Spring Security Reference].
Extensive JavaDoc for the Spring Security code is also available in the https://docs.spring.io/spring-security/site/docs/current/api/[Spring Security API Documentation].

== Quick Start
See https://docs.spring.io/spring-security/site/docs/current/reference/html5/#servlet-hello[Hello Spring Security] to get started with a "Hello, World" application.

== Building from Source
Spring Security uses a https://gradle.org[Gradle]-based build system.
In the instructions below, https://vimeo.com/34436402[`./gradlew`] is invoked from the root of the source tree and serves as
a cross-platform, self-contained bootstrap mechanism for the build.

=== Prerequisites
https://docs.github.com/en/get-started/quickstart/set-up-git[Git] and the https://www.oracle.com/java/technologies/downloads/#java17[JDK17 build].

Be sure that your `JAVA_HOME` environment variable points to the `jdk-17` folder extracted from the JDK download.

=== Check out sources
[indent=0]
----
git clone git@github.com:spring-projects/spring-security.git
----

=== Install all `spring-*.jar` into your local Maven repository.

[indent=0]
----
./gradlew publishToMavenLocal
----

=== Compile and test; build all JARs, distribution zips, and docs

[indent=0]
----
./gradlew build
----

The reference docs are not currently included in the distribution zip.
You can build the reference docs for this branch by running the following command:

----
./gradlew :spring-security-docs:antora
----

That command publishes the docs site to the `_docs/build/site_` directory.
The https://github.com/spring-projects/spring-security/tree/docs-build[playbook branch] describes how to build the reference docs in detail.

Discover more commands with `./gradlew tasks`.

== Getting Support
Check out the https://stackoverflow.com/questions/tagged/spring-security[Spring Security tags on Stack Overflow].
https://spring.io/support[Commercial support] is available too.

== Contributing
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request[Pull requests] are welcome; see the https://github.com/spring-projects/spring-security/blob/main/CONTRIBUTING.adoc[contributor guidelines] for details.

== License
Spring Security is Open Source software released under the
https://www.apache.org/licenses/LICENSE-2.0.html[Apache 2.0 license].