-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Pull requests: spring-projects/spring-security
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Allow specifying a ServerAuthenticationConverter for x509()
status: waiting-for-triage
An issue we've not yet triaged
#17382
opened Jun 27, 2025 by
blake-bauman
Loading…
Allow multiple ServerLogoutHandler instances in WebFlux
status: waiting-for-triage
An issue we've not yet triaged
#17381
opened Jun 27, 2025 by
blake-bauman
Loading…
Remove An issue we've not yet triaged
AllowFromStrategy
in favor of ContentSecurityPolicy
status: waiting-for-triage
#17358
opened Jun 25, 2025 by
therepanic
Loading…
Fix equals and hashCode in An issue we've not yet triaged
PathPatternRequestMatcher
to include HTTP method
status: waiting-for-triage
#17337
opened Jun 23, 2025 by
therepanic
Loading…
Remove deprecated classes moved to other packages
in: core
An issue in spring-security-core
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove RelyingPartyRegistration deprecations
in: saml2
An issue in SAML2 modules
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove Nimbus(Reactive)OpaqueTokenIntrospector
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Use An issue in spring-security-ldap
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
LdapName
instead of DistinguishedName
in: ldap
Convert to use LdapClient instead of SpringSecurityLdapTemplate in Pa…
status: waiting-for-triage
An issue we've not yet triaged
#17324
opened Jun 21, 2025 by
minkukjo
Loading…
Default to XorCsrfChannelInterceptor in XML configuration
status: waiting-for-triage
An issue we've not yet triaged
#17323
opened Jun 20, 2025 by
msqr
Loading…
Remove deprecated elements using AuthorizationDecision
status: waiting-for-triage
An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
#17322
opened Jun 20, 2025 by
ngocnhan-tran1996
Loading…
Remove An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
RequestVariablesExtractor
in favor of RequestMatcher#matcher
status: waiting-for-triage
#17320
opened Jun 20, 2025 by
therepanic
Loading…
Fixed link to CSRF checks on rubyonrails.org site
status: waiting-for-triage
An issue we've not yet triaged
#17319
opened Jun 20, 2025 by
fa11enangel
Loading…
Adjust log message to include guidance for XML users
status: waiting-for-triage
An issue we've not yet triaged
#17317
opened Jun 20, 2025 by
x7Git
Loading…
Remove deprecated elements from DaoAuthenticationProvider
status: waiting-for-triage
An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
#17315
opened Jun 19, 2025 by
ngocnhan-tran1996
Loading…
Removed deprecated Base64 of crypto package
status: waiting-for-triage
An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
#17314
opened Jun 19, 2025 by
ronodhirSoumik
Loading…
Remove deprecated elements of RoleHierarchyImpl
status: waiting-for-triage
An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
#17313
opened Jun 19, 2025 by
ngocnhan-tran1996
Loading…
Remove PrePostTemplateDefaults
status: waiting-for-triage
An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
#17312
opened Jun 19, 2025 by
ngocnhan-tran1996
Loading…
Remove EnableWebMvcSecurity
status: waiting-for-triage
An issue we've not yet triaged
type: breaks-passivity
A change that breaks passivity with the previous release
#17311
opened Jun 19, 2025 by
ngocnhan-tran1996
Loading…
Polish
status: waiting-for-triage
An issue we've not yet triaged
#17310
opened Jun 18, 2025 by
ngocnhan-tran1996
Loading…
Improve authoritiesClaimName validation in JwtGrantedAuthoritiesConverter
status: waiting-for-triage
An issue we've not yet triaged
#17247
opened Jun 14, 2025 by
chanbinme
Loading…
Ensure ID Token is updated after refresh token (Reactive)
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Fix PublicKeyCredentialType.PUBLIC_KEY comparison with Spring Session
in: web
An issue in web modules (web, webmvc)
status: waiting-for-feedback
We need additional information before we can continue
type: bug
A general bug
#17223
opened Jun 10, 2025 by
ltanguy
Loading…
Add Support DPoP Customization
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Support custom An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
OAuth2AuthenticatedPrincipal
in Jwt-based authentication flow
in: oauth2
#17191
opened Jun 1, 2025 by
therepanic
Loading…
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.