-
Notifications
You must be signed in to change notification settings - Fork 5.9k
Issues: spring-projects/spring-security
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Automatically apply Customizer Beans to the Security DSL
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
Add support fullyAuthenticated to Kotlin DSL
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
Leave Filter Chain Observations Off By Default
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Consider favoring ObjectProvider#getIfAvailable
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Provide a way to customize the default RequestCache without replacing the entire implementation
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#15707
opened Aug 28, 2024 by
eric-creekside
Remove An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
authorizeRequests
from Kotlin DSL
in: config
LogoutConfigurer forces POST even if CSRF is disabled for /logout
in: config
An issue in spring-security-config
status: feedback-provided
Feedback has been provided
type: enhancement
A general enhancement
#14913
opened Apr 15, 2024 by
erizzo
AnonymousConfigurer.authorities only accepts GrantedAuthorities but no subtypes of GrantedAuthorities
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
Fix Customizer.withDefaults() for authorizeHttpRequests
for: team-attention
This ticket should be discussed as a team before proceeding
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#14344
opened Dec 18, 2023 by
manueljordan
Endpoint filters should be reachable when using An issue in spring-security-config
type: enhancement
A general enhancement
spring.mvc.servlet.path
in: config
#14230
opened Dec 1, 2023 by
ldcsaa
Consider warning users if securityMatchers do not match some filter in the chain
in: config
An issue in spring-security-config
status: ideal-for-contribution
An issue that we actively are looking for someone to help us with
type: enhancement
A general enhancement
#14096
opened Nov 4, 2023 by
Haarolean
Improve CVE-2023-34035 detection
in: config
An issue in spring-security-config
type: bug
A general bug
#13568
opened Jul 20, 2023 by
dreis2211
5 of 6 tasks
Default Servlet Headers Should Include Referrer-Policy
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Simplify MvcRequestMatcher construction
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#13562
opened Jul 18, 2023 by
jzheaux
Updating to mockito 4.11.0 causes OAuth2LoginBeanDefinitionParserTests and OAuth2ClientBeanDefinitionParserTests to fail
in: config
An issue in spring-security-config
type: bug
A general bug
#13546
opened Jul 15, 2023 by
jzheaux
Remove AbstractConfiguredSecurityBuilder#apply
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Customizable set of JwtClaimValidators for OAuth Resource Server
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#13249
opened May 31, 2023 by
romangr
Align Return Types of no-arg and Customizer arg Configuration Methods
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
#13093
opened Apr 25, 2023 by
marcusdacoregio
Remove .and() and non lambda methods from DSL
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Add remaining lambda methods to configuration
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#13003
opened Apr 12, 2023 by
marcusdacoregio
6 tasks
Consider erroring when client authentication method is basic
in: config
An issue in spring-security-config
type: bug
A general bug
#12585
opened Jan 25, 2023 by
jzheaux
Remove shouldFilterAllDispatcherTypes
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Resolve ContentNegotiationStrategy from ApplicationContext
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#12028
opened Oct 17, 2022 by
marcusdacoregio
SecurityContextHolderStrategy bean should be copied to SecurityContextHolder by default
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
HttpSecurity bean has no option to disable defaults
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
#11633
opened Jul 27, 2022 by
filiphr
Previous Next
ProTip!
Exclude everything labeled
bug
with -label:bug.