GitHub / spring-projects/spring-security issues and pull requests
#17531 - [OAuth2 Client] cannot access org.springframework.web.reactive.function.client.ExchangeFilterFunction
Issue -
State: open - Opened by palatam 14 days ago
Labels: status: waiting-for-triage, type: bug
#17530 - Bump org.apache.maven:maven-resolver-provider from 3.9.10 to 3.9.11
Pull Request -
State: open - Opened by dependabot[bot] 14 days ago
Labels: type: dependency-upgrade
#17526 - Bump io.projectreactor:reactor-bom from 2025.0.0-M4 to 2025.0.0-M5
Pull Request -
State: open - Opened by dependabot[bot] 14 days ago
Labels: type: dependency-upgrade
#17523 - Add type-safe `getPrincipal(Class<T>)` method to Authentication
Issue -
State: closed - Opened by wsdf25867 16 days ago
- 1 comment
Labels: status: waiting-for-triage, type: enhancement
#17511 - Address Incorrect scope map fix in Reactive service
Pull Request -
State: open - Opened by asinghania71 19 days ago
Labels: status: waiting-for-triage
#17510 - Gh 12144
Pull Request -
State: closed - Opened by asinghania71 19 days ago
Labels: status: waiting-for-triage
#17509 - Add 7.0 Migration Steps for Messaging PathPattern Usage
Issue -
State: closed - Opened by jzheaux 20 days ago
Labels: in: messaging, type: bug
#17508 - Websocket XML config should pick up PathPatternMessageMatcher.Builder
Issue -
State: closed - Opened by jzheaux 20 days ago
Labels: in: messaging, type: bug
#17507 - PKCE configuration - enabled by default
Pull Request -
State: open - Opened by rohan-naik07 20 days ago
Labels: status: waiting-for-triage
#17506 - Add disable DSL for RequestCache
Pull Request -
State: open - Opened by Rattiel 20 days ago
Labels: status: waiting-for-triage
#17505 - Remove shouldFilterAllDispatcherTypes
Pull Request -
State: open - Opened by kse-music 20 days ago
- 1 comment
Labels: in: config, type: enhancement, status: feedback-provided, type: breaks-passivity
#17504 - Simplify Expression Migration for authorizeRequests
Issue -
State: closed - Opened by jzheaux 21 days ago
Labels: in: web, type: enhancement
#17503 - Support Filtering Events in SpringAuthorizationEventPublisher
Issue -
State: closed - Opened by jzheaux 21 days ago
Labels: in: core, type: enhancement
#17502 - Fix securityContextRepository() initialization in oauth2Login() DSL
Pull Request -
State: open - Opened by marcusdacoregio 21 days ago
Labels: status: waiting-for-triage
#17501 - Remove usage of PathMatcher in messaging
Issue -
State: closed - Opened by jzheaux 21 days ago
Labels: in: messaging, type: enhancement, type: breaks-passivity
#17500 - Make stricter IP format check in `IpAddressMatcher`
Pull Request -
State: open - Opened by therepanic 22 days ago
- 1 comment
Labels: status: waiting-for-triage
#17499 - IpAddressMatcher allows hostnames
Issue -
State: open - Opened by levry 22 days ago
- 3 comments
Labels: status: waiting-for-triage, type: bug
#17498 - Remove AbstractConfiguredSecurityBuilder apply method
Pull Request -
State: closed - Opened by kse-music 22 days ago
- 1 comment
Labels: in: config, type: enhancement, type: breaks-passivity
#17497 - Allow all HttpSecurity DSL methods to apply Customizer.withDefaults() by default
Issue -
State: open - Opened by DeepDhamala 22 days ago
Labels: status: waiting-for-triage, type: enhancement
#17496 - Use UserWebTestClientConfigurer
Issue -
State: closed - Opened by rwinch 23 days ago
Labels: in: build, type: enhancement
#17495 - `<websocket-message-broker>` should pick up a bean named `csrfChannelInterceptor`
Issue -
State: closed - Opened by jzheaux 23 days ago
Labels: in: config, in: messaging, type: bug, status: forward-port
#17494 - `<websocket-message-broker>` should pick up a bean named `csrfChannelInterceptor`
Issue -
State: closed - Opened by jzheaux 23 days ago
Labels: in: config, in: messaging, type: bug, status: forward-port
#17493 - `<websocket-message-broker>` should pick up a bean named `csrfChannelInterceptor`
Issue -
State: closed - Opened by jzheaux 23 days ago
Labels: in: config, in: messaging, type: bug
#17492 - Add lambda DSL method for featurePolicy
Pull Request -
State: open - Opened by therepanic 23 days ago
- 1 comment
Labels: status: waiting-for-triage
#17491 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.20.Final
Pull Request -
State: closed - Opened by dependabot[bot] 23 days ago
- 2 comments
Labels: type: dependency-upgrade
#17490 - Bump org.hibernate.orm:hibernate-core from 6.6.19.Final to 6.6.20.Final
Pull Request -
State: closed - Opened by dependabot[bot] 23 days ago
- 2 comments
Labels: type: dependency-upgrade
#17489 - Bump org.hibernate.orm:hibernate-core from 7.0.4.Final to 7.0.5.Final
Pull Request -
State: closed - Opened by dependabot[bot] 23 days ago
- 2 comments
Labels: type: dependency-upgrade
#17488 - Fix Error message for unsupported Spring Security XSD versions
Pull Request -
State: open - Opened by DeepDhamala 23 days ago
Labels: status: waiting-for-triage
#17487 - @PreAuthorize not working in Spring Security 6+ due to deprecation
Issue -
State: open - Opened by armorcodehemant 25 days ago
Labels: status: waiting-for-triage, type: enhancement
#17486 - Update JwtIssuerAuthenticationManagerResolver constructor javadoc
Pull Request -
State: closed - Opened by ngocnhan-tran1996 25 days ago
- 1 comment
Labels: in: docs, type: bug
#17485 - Implement equals and hashCode in `OidcIdToken`
Pull Request -
State: open - Opened by therepanic 26 days ago
Labels: status: waiting-for-triage
#17484 - HttpSecurity.build() in a bean method that defines a security filter chain triggers a BeanCurrentlyInCreationException
Issue -
State: closed - Opened by wilkinsona 26 days ago
Labels: in: config, type: bug
#17483 - Bump com.webauthn4j:webauthn4j-core from 0.29.3.RELEASE to 0.29.4.RELEASE
Pull Request -
State: closed - Opened by dependabot[bot] 26 days ago
- 2 comments
Labels: type: dependency-upgrade
#17482 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final
Pull Request -
State: closed - Opened by dependabot[bot] 26 days ago
- 1 comment
Labels: type: dependency-upgrade
#17481 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: closed - Opened by dependabot[bot] 26 days ago
- 2 comments
Labels: type: dependency-upgrade
#17480 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7
Pull Request -
State: closed - Opened by dependabot[bot] 26 days ago
- 2 comments
Labels: type: dependency-upgrade
#17479 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] 26 days ago
- 1 comment
Labels: type: dependency-upgrade
#17478 - Bump com.webauthn4j:webauthn4j-core from 0.29.3.RELEASE to 0.29.4.RELEASE
Pull Request -
State: closed - Opened by dependabot[bot] 26 days ago
- 2 comments
Labels: type: dependency-upgrade
#17477 - Update Shibboleth repository URL
Pull Request -
State: open - Opened by bernie-schelberg-invicara 27 days ago
Labels: status: waiting-for-triage
#17474 - docs: fix typo in @AuthenticationPrincipal documentation
Pull Request -
State: closed - Opened by harcomaase 27 days ago
Labels: status: waiting-for-triage
#17472 - Change log level from debug to warn for request rejection logging
Pull Request -
State: closed - Opened by seungh0 27 days ago
- 2 comments
Labels: status: waiting-for-triage, type: enhancement, status: declined
#17465 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17464 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17463 - Bump org-apache-maven-resolver from 1.9.23 to 1.9.24
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17462 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17461 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17455 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17454 - Bump org.springframework.data:spring-data-bom from 2024.0.12 to 2024.0.13
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17453 - Bump org.springframework:spring-framework-bom from 6.1.20 to 6.1.21
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17452 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17451 - Bump org-apache-maven-resolver from 1.9.23 to 1.9.24
Pull Request -
State: closed - Opened by dependabot[bot] 27 days ago
Labels: in: build, type: dependency-upgrade
#17425 - Improve logging clarity in CsrfFilter
Pull Request -
State: closed - Opened by DeepDhamala 29 days ago
- 2 comments
Labels: in: web, type: enhancement
#17424 - ClientRegistration.Builder.tokenUri() should take a `URI` parameter, not a `String`
Issue -
State: closed - Opened by walles 29 days ago
- 3 comments
Labels: type: enhancement, status: declined, in: oauth2
#17423 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17422 - Bump com.fasterxml.jackson:jackson-bom from 2.19.0 to 2.19.1
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17421 - Bump io.mockk:mockk from 1.14.2 to 1.14.4
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17420 - Bump org.hibernate.orm:hibernate-core from 7.0.1.Final to 7.0.4.Final
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17419 - Bump org.springframework.data:spring-data-bom from 2024.0.12 to 2024.0.13
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17418 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17417 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17416 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17415 - Bump org.springframework:spring-framework-bom from 6.1.20 to 6.1.21
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17414 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17413 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17412 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17411 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17410 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17409 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17408 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17407 - Bump io.mockk:mockk from 1.14.2 to 1.14.4
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17406 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17405 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7
Pull Request -
State: open - Opened by dependabot[bot] 29 days ago
Labels: type: dependency-upgrade
#17404 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17403 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17402 - Bump io.mockk:mockk from 1.14.2 to 1.14.4
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17401 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17400 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17399 - Bump org.hibernate.orm:hibernate-core from 7.0.1.Final to 7.0.4.Final
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17398 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17397 - Bump com.fasterxml.jackson:jackson-bom from 2.19.0 to 2.19.1
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17396 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17395 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17394 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17393 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17392 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.19.Final
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17391 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17390 - Bump org.springframework.data:spring-data-bom from 2024.1.6 to 2024.1.7
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17389 - Bump io-spring-javaformat from 0.0.46 to 0.0.47
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17388 - Bump org.springframework.ldap:spring-ldap-core from 3.2.12 to 3.2.13
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17387 - Bump org.springframework:spring-framework-bom from 6.1.20 to 6.1.21
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17386 - Bump org.springframework.data:spring-data-bom from 2024.0.12 to 2024.0.13
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17385 - Stub the call to OpenID configuration in an `oauth2Client` `@SpringBootTest`
Issue -
State: open - Opened by ch4mpy about 1 month ago
- 2 comments
Labels: status: waiting-for-triage, type: enhancement
#17384 - Change `FilterBasedLdapUserSearch` to use `LdapClient`
Pull Request -
State: open - Opened by therepanic about 1 month ago
Labels: status: waiting-for-triage
#17383 - Fail resolve argument CustomUserDetails when I test in only SecurityAutoConfiguration and @WebMvcTest
Issue -
State: open - Opened by hky035 about 1 month ago
Labels: status: waiting-for-triage, type: bug
#17382 - Allow specifying a ServerAuthenticationConverter for x509()
Pull Request -
State: open - Opened by blake-bauman about 1 month ago
Labels: status: waiting-for-triage
#17381 - Allow multiple ServerLogoutHandler instances in WebFlux
Pull Request -
State: open - Opened by blake-bauman about 1 month ago
Labels: status: waiting-for-triage
#17380 - Update to Kotlin 2.2
Pull Request -
State: closed - Opened by rwinch about 1 month ago
Labels: type: dependency-upgrade
#17379 - OAuth2: ServletOAuth2AuthorizedClientExchangeFilterFunction can fail to remove client if webclient receives retryable responses.
Issue -
State: open - Opened by jjstreet about 1 month ago
- 4 comments
Labels: status: waiting-for-triage, type: bug
#17378 - Bump org.springframework:spring-framework-bom from 6.2.7 to 6.2.8
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade
#17377 - Bump org.hibernate.orm:hibernate-core from 6.6.17.Final to 6.6.18.Final
Pull Request -
State: closed - Opened by dependabot[bot] about 1 month ago
Labels: type: dependency-upgrade