-
Notifications
You must be signed in to change notification settings - Fork 5.9k
Issues: spring-projects/spring-security
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Add ServerWebExchange parameter to AuthorizationRequestCustomizer
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-triage
An issue we've not yet triaged
type: enhancement
A general enhancement
#16320
opened Dec 20, 2024 by
kse-music
Loading…
Pass Http Request to OAuth2AuthorizationRequestResolver#authorizationRequestCustomizer
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-triage
An issue we've not yet triaged
type: enhancement
A general enhancement
#16306
opened Dec 19, 2024 by
ZIRAKrezovic
Consider adding An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
PrincipalResolver
to ExchangeFilterFunctions
in: oauth2
Remove Deprecated Usages of RemoteJWKSet
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16251
opened Dec 9, 2024 by
jzheaux
The selectJwk method of NimbusJwtEncoder class should not throw Exception when jwks size great than one
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: ideal-for-contribution
An issue that we actively are looking for someone to help us with
type: enhancement
A general enhancement
#16170
opened Nov 26, 2024 by
douxiaofeng99
Consider using An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
@Fallback
instead of BeanDefinitionRegistryPostProcessor
for OAuth2AuthorizedClientManager
in: oauth2
[OAuth2] Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-triage
An issue we've not yet triaged
type: bug
A general bug
OidcBackChannelLogoutWebFilter returns an error for unauthenticated ajax requests
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-triage
An issue we've not yet triaged
type: bug
A general bug
#16073
opened Nov 12, 2024 by
katya-tis
Do not validate parameters in An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: bug
A general bug
ServerBearerTokenAuthenticationConverter
and DefaultBearerTokenResolver
if not enabled
in: oauth2
#16039
opened Nov 5, 2024 by
jonah1und1
Loading…
ServerBearerTokenAuthenticationConverter
validates parameters when not enabled
in: oauth2
Encode clientId and clientSecret for An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: blocked
An issue that's blocked on an external project change
type: bug
A general bug
OpaqueTokenIntrospector
and ReactiveOpaqueTokenIntrospector
in: oauth2
Expose getter for nameAttributeKey in OAuth2AuthenticatedPrincipal
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Consider aligning OAuth 2.0 Access Token Response parsing in BodyExtractor
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Implementations of OpaqueTokenIntrospector fail to URL encode client secret
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: bug
A general bug
Upgrade nimbus-jose-jwt:jar to 9.37.3 in Spring Security 5.8.x
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: feedback-provided
Feedback has been provided
type: dependency-upgrade
A dependency upgrade
#15951
opened Oct 18, 2024 by
blackat
Add support for custom grant types
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#15884
opened Oct 7, 2024 by
sjohnr
Loading…
Allow comma-delimited scopes in OAuth2 access token response
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#15878
opened Oct 5, 2024 by
bfanyuk
Add An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
OAuth2AuthorizedClientManager
autoconfiguration without spring-boot-starter-web
dependency
in: oauth2
#15877
opened Oct 4, 2024 by
yvasyliev
Consider adding An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
ClientRegistrationIdResolver
to ExchangeFilterFunction
s
in: oauth2
Add support for requesting protected resources with An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
RestClient
similar to ServletBearerExchangeFilterFunction
in: oauth2
Add support for access token in body parameter as per rfc 6750 Sec. 2.2
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
ServerBearerTokenAuthenticationConverter does not support form encoded body parameter
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: duplicate
A duplicate of another issue
type: enhancement
A general enhancement
Consider removing one level of the OIDC Backchannel Logout DSL
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Consider adding a discovery client for An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
ClientRegistrations
in: oauth2
#15590
opened Aug 13, 2024 by
sjohnr
Authentication
in the security context is not updated during the refresh token flow
in: oauth2
#15509
opened Aug 1, 2024 by
ch4mpy
Previous Next
ProTip!
Updated in the last three days: updated:>2024-12-28.