An open API service for providing issue and pull request metadata for open source projects.

GitHub / spring-projects/spring-security issues and pull requests

#17531 - [OAuth2 Client] cannot access org.springframework.web.reactive.function.client.ExchangeFilterFunction

Issue - State: open - Opened by palatam 14 days ago
Labels: status: waiting-for-triage, type: bug

#17530 - Bump org.apache.maven:maven-resolver-provider from 3.9.10 to 3.9.11

Pull Request - State: open - Opened by dependabot[bot] 14 days ago
Labels: type: dependency-upgrade

#17526 - Bump io.projectreactor:reactor-bom from 2025.0.0-M4 to 2025.0.0-M5

Pull Request - State: open - Opened by dependabot[bot] 14 days ago
Labels: type: dependency-upgrade

#17523 - Add type-safe `getPrincipal(Class<T>)` method to Authentication

Issue - State: closed - Opened by wsdf25867 16 days ago - 1 comment
Labels: status: waiting-for-triage, type: enhancement

#17511 - Address Incorrect scope map fix in Reactive service

Pull Request - State: open - Opened by asinghania71 19 days ago
Labels: status: waiting-for-triage

#17510 - Gh 12144

Pull Request - State: closed - Opened by asinghania71 19 days ago
Labels: status: waiting-for-triage

#17509 - Add 7.0 Migration Steps for Messaging PathPattern Usage

Issue - State: closed - Opened by jzheaux 20 days ago
Labels: in: messaging, type: bug

#17508 - Websocket XML config should pick up PathPatternMessageMatcher.Builder

Issue - State: closed - Opened by jzheaux 20 days ago
Labels: in: messaging, type: bug

#17507 - PKCE configuration - enabled by default

Pull Request - State: open - Opened by rohan-naik07 20 days ago
Labels: status: waiting-for-triage

#17506 - Add disable DSL for RequestCache

Pull Request - State: open - Opened by Rattiel 20 days ago
Labels: status: waiting-for-triage

#17505 - Remove shouldFilterAllDispatcherTypes

Pull Request - State: open - Opened by kse-music 20 days ago - 1 comment
Labels: in: config, type: enhancement, status: feedback-provided, type: breaks-passivity

#17504 - Simplify Expression Migration for authorizeRequests

Issue - State: closed - Opened by jzheaux 21 days ago
Labels: in: web, type: enhancement

#17503 - Support Filtering Events in SpringAuthorizationEventPublisher

Issue - State: closed - Opened by jzheaux 21 days ago
Labels: in: core, type: enhancement

#17502 - Fix securityContextRepository() initialization in oauth2Login() DSL

Pull Request - State: open - Opened by marcusdacoregio 21 days ago
Labels: status: waiting-for-triage

#17501 - Remove usage of PathMatcher in messaging

Issue - State: closed - Opened by jzheaux 21 days ago
Labels: in: messaging, type: enhancement, type: breaks-passivity

#17500 - Make stricter IP format check in `IpAddressMatcher`

Pull Request - State: open - Opened by therepanic 22 days ago - 1 comment
Labels: status: waiting-for-triage

#17499 - IpAddressMatcher allows hostnames

Issue - State: open - Opened by levry 22 days ago - 3 comments
Labels: status: waiting-for-triage, type: bug

#17498 - Remove AbstractConfiguredSecurityBuilder apply method

Pull Request - State: closed - Opened by kse-music 22 days ago - 1 comment
Labels: in: config, type: enhancement, type: breaks-passivity

#17497 - Allow all HttpSecurity DSL methods to apply Customizer.withDefaults() by default

Issue - State: open - Opened by DeepDhamala 22 days ago
Labels: status: waiting-for-triage, type: enhancement

#17496 - Use UserWebTestClientConfigurer

Issue - State: closed - Opened by rwinch 23 days ago
Labels: in: build, type: enhancement

#17495 - `<websocket-message-broker>` should pick up a bean named `csrfChannelInterceptor`

Issue - State: closed - Opened by jzheaux 23 days ago
Labels: in: config, in: messaging, type: bug, status: forward-port

#17494 - `<websocket-message-broker>` should pick up a bean named `csrfChannelInterceptor`

Issue - State: closed - Opened by jzheaux 23 days ago
Labels: in: config, in: messaging, type: bug, status: forward-port

#17493 - `<websocket-message-broker>` should pick up a bean named `csrfChannelInterceptor`

Issue - State: closed - Opened by jzheaux 23 days ago
Labels: in: config, in: messaging, type: bug

#17492 - Add lambda DSL method for featurePolicy

Pull Request - State: open - Opened by therepanic 23 days ago - 1 comment
Labels: status: waiting-for-triage

#17491 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.20.Final

Pull Request - State: closed - Opened by dependabot[bot] 23 days ago - 2 comments
Labels: type: dependency-upgrade

#17490 - Bump org.hibernate.orm:hibernate-core from 6.6.19.Final to 6.6.20.Final

Pull Request - State: closed - Opened by dependabot[bot] 23 days ago - 2 comments
Labels: type: dependency-upgrade

#17489 - Bump org.hibernate.orm:hibernate-core from 7.0.4.Final to 7.0.5.Final

Pull Request - State: closed - Opened by dependabot[bot] 23 days ago - 2 comments
Labels: type: dependency-upgrade

#17488 - Fix Error message for unsupported Spring Security XSD versions

Pull Request - State: open - Opened by DeepDhamala 23 days ago
Labels: status: waiting-for-triage

#17487 - @PreAuthorize not working in Spring Security 6+ due to deprecation

Issue - State: open - Opened by armorcodehemant 25 days ago
Labels: status: waiting-for-triage, type: enhancement

#17486 - Update JwtIssuerAuthenticationManagerResolver constructor javadoc

Pull Request - State: closed - Opened by ngocnhan-tran1996 25 days ago - 1 comment
Labels: in: docs, type: bug

#17485 - Implement equals and hashCode in `OidcIdToken`

Pull Request - State: open - Opened by therepanic 26 days ago
Labels: status: waiting-for-triage

#17483 - Bump com.webauthn4j:webauthn4j-core from 0.29.3.RELEASE to 0.29.4.RELEASE

Pull Request - State: closed - Opened by dependabot[bot] 26 days ago - 2 comments
Labels: type: dependency-upgrade

#17482 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final

Pull Request - State: closed - Opened by dependabot[bot] 26 days ago - 1 comment
Labels: type: dependency-upgrade

#17481 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: closed - Opened by dependabot[bot] 26 days ago - 2 comments
Labels: type: dependency-upgrade

#17480 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7

Pull Request - State: closed - Opened by dependabot[bot] 26 days ago - 2 comments
Labels: type: dependency-upgrade

#17479 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] 26 days ago - 1 comment
Labels: type: dependency-upgrade

#17478 - Bump com.webauthn4j:webauthn4j-core from 0.29.3.RELEASE to 0.29.4.RELEASE

Pull Request - State: closed - Opened by dependabot[bot] 26 days ago - 2 comments
Labels: type: dependency-upgrade

#17477 - Update Shibboleth repository URL

Pull Request - State: open - Opened by bernie-schelberg-invicara 27 days ago
Labels: status: waiting-for-triage

#17474 - docs: fix typo in @AuthenticationPrincipal documentation

Pull Request - State: closed - Opened by harcomaase 27 days ago
Labels: status: waiting-for-triage

#17472 - Change log level from debug to warn for request rejection logging

Pull Request - State: closed - Opened by seungh0 27 days ago - 2 comments
Labels: status: waiting-for-triage, type: enhancement, status: declined

#17465 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17464 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17463 - Bump org-apache-maven-resolver from 1.9.23 to 1.9.24

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17462 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17461 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17455 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17454 - Bump org.springframework.data:spring-data-bom from 2024.0.12 to 2024.0.13

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17453 - Bump org.springframework:spring-framework-bom from 6.1.20 to 6.1.21

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17452 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17451 - Bump org-apache-maven-resolver from 1.9.23 to 1.9.24

Pull Request - State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade

#17425 - Improve logging clarity in CsrfFilter

Pull Request - State: closed - Opened by DeepDhamala 29 days ago - 2 comments
Labels: in: web, type: enhancement

#17424 - ClientRegistration.Builder.tokenUri() should take a `URI` parameter, not a `String`

Issue - State: closed - Opened by walles 29 days ago - 3 comments
Labels: type: enhancement, status: declined, in: oauth2

#17423 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17422 - Bump com.fasterxml.jackson:jackson-bom from 2.19.0 to 2.19.1

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17421 - Bump io.mockk:mockk from 1.14.2 to 1.14.4

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17420 - Bump org.hibernate.orm:hibernate-core from 7.0.1.Final to 7.0.4.Final

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17419 - Bump org.springframework.data:spring-data-bom from 2024.0.12 to 2024.0.13

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17418 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17417 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17416 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17415 - Bump org.springframework:spring-framework-bom from 6.1.20 to 6.1.21

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17414 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17413 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17412 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17411 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17410 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17409 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17408 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17407 - Bump io.mockk:mockk from 1.14.2 to 1.14.4

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17406 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17405 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7

Pull Request - State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade

#17404 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17403 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17402 - Bump io.mockk:mockk from 1.14.2 to 1.14.4

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17401 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17400 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17399 - Bump org.hibernate.orm:hibernate-core from 7.0.1.Final to 7.0.4.Final

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17398 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17397 - Bump com.fasterxml.jackson:jackson-bom from 2.19.0 to 2.19.1

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17396 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17395 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17394 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17393 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17392 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17391 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17390 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17389 - Bump io-spring-javaformat from 0.0.46 to 0.0.47

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17388 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17387 - Bump org.springframework:spring-framework-bom from 6.1.20 to 6.1.21

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17386 - Bump org.springframework.data:spring-data-bom from 2024.0.12 to 2024.0.13

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17385 - Stub the call to OpenID configuration in an `oauth2Client` `@SpringBootTest`

Issue - State: open - Opened by ch4mpy about 1 month ago - 2 comments
Labels: status: waiting-for-triage, type: enhancement

#17384 - Change `FilterBasedLdapUserSearch` to use `LdapClient`

Pull Request - State: open - Opened by therepanic about 1 month ago
Labels: status: waiting-for-triage

#17383 - Fail resolve argument CustomUserDetails when I test in only SecurityAutoConfiguration and @WebMvcTest

Issue - State: open - Opened by hky035 about 1 month ago
Labels: status: waiting-for-triage, type: bug

#17382 - Allow specifying a ServerAuthenticationConverter for x509()

Pull Request - State: open - Opened by blake-bauman about 1 month ago
Labels: status: waiting-for-triage

#17381 - Allow multiple ServerLogoutHandler instances in WebFlux

Pull Request - State: open - Opened by blake-bauman about 1 month ago
Labels: status: waiting-for-triage

#17380 - Update to Kotlin 2.2

Pull Request - State: closed - Opened by rwinch about 1 month ago
Labels: type: dependency-upgrade

#17379 - OAuth2: ServletOAuth2AuthorizedClientExchangeFilterFunction can fail to remove client if webclient receives retryable responses.

Issue - State: open - Opened by jjstreet about 1 month ago - 4 comments
Labels: status: waiting-for-triage, type: bug

#17378 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade

#17377 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.18.Final

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade