Commit Graph

35121 Commits (ed80241a800f197c8484ac40f42ffe34c562cdb7)
 

Author SHA1 Message Date
Stephane Nicoll ed80241a80 Merge branch '2.6.x' into 2.7.x 3 years ago
Stephane Nicoll 272e08ad1a Merge branch '2.5.x' into 2.6.x 3 years ago
Stephane Nicoll 84ef1f7c21 Upgrade to Log4j2 2.17.0
Closes gh-28985
3 years ago
Stephane Nicoll 012fbdd43d Upgrade to Log4j2 2.17.0
Closes gh-28984
3 years ago
Stephane Nicoll cb02944c71 Upgrade to Log4j2 2.17.0
Closes gh-28983
3 years ago
Madhura Bhave d803c53e02 Merge branch '2.6.x' into 2.7.x
Closes gh-29109
3 years ago
Madhura Bhave 4cc8012bfa Handle WebServerNamespace in CachingOperationInvoker
Fixes gh-28882
3 years ago
Madhura Bhave 764531c326 Merge branch '2.6.x' into 2.7.x
Closes gh-29108
3 years ago
Madhura Bhave d9d161cd6b Allow previously authorized users to access the error page
Prior to this commit, the `ErrorPageSecurityFilter` verified if
access to the error page was allowed by invoking the
`WebInvocationPrivilegeEvaluator` with the Authentication from the
`SecurityContextHolder`.
This meant that access to the error page was denied for a `null` Authentication
 or `AnonymousAuthenticationToken` in cases where the error page required
authenticated access. This prevented authorized users from accessing the
error page in case the Authentication wasn't retrievable for the error dispatch,
which is the case for `@Transient` authentication or stateless session policy.

This commit updates the `ErrorPageSecurityFilter` to check access to the error page
only if the error is an authn or authz error in cases where an authentication object
is not found in the SecurityContextHolder. This makes the error response consistent
when bad credentials or no credentials are used while also allowing access to previously
authorized users.

Fixes gh-28953
3 years ago
Stephane Nicoll 64dd1f86c0 Merge branch '2.6.x' into 2.7.x
Closes gh-29104
3 years ago
Stephane Nicoll c077ebecf7 Merge branch '2.5.x' into 2.6.x
Closes gh-29103
3 years ago
Andy Wilkinson 2fec06ac7e Find annotation without initializing factory beans
Closes gh-28977
3 years ago
Brian Clozel b04f7904ff Merge branch '2.6.x' into 2.7.x
Closes gh-29013
3 years ago
Brian Clozel 1c35ec2c3c Merge branch '2.5.x' into 2.6.x
Closes gh-29012
3 years ago
Brian Clozel 5d0206320a Upgrade to Logback 1.2.9
Closes gh-29011
3 years ago
Stephane Nicoll de383fcee0 Merge branch '2.6.x' into 2.7.x
Closes gh-29099
3 years ago
Stephane Nicoll bcaa59ce73 Merge branch '2.5.x' into 2.6.x
Closes gh-29098
3 years ago
Stephane Nicoll 614d34195a Merge pull request #29094 from An1s9n
* pr/29094:
  Polish CacheManager customization section in reference doc

Closes gh-29094
3 years ago
Pavel Anisimov 415c58e21b Polish CacheManager customization section in reference doc
See gh-29094
3 years ago
Stephane Nicoll a05714ad9f Merge branch '2.6.x' into 2.7.x
Closes gh-29097
3 years ago
Stephane Nicoll 10362a9315 Merge branch '2.5.x' into 2.6.x
Closes gh-29096
3 years ago
Stephane Nicoll 8c9d398422 Test our Gradle plugin against Gradle 7.3.2
Closes gh-29093
3 years ago
Phillip Webb 1015df088d Merge branch '2.6.x' into 2.7.x 3 years ago
Phillip Webb 587d6fa309 Polish 3 years ago
Phillip Webb 9c36682fe7 Merge branch '2.6.x' into 2.7.x 3 years ago
Phillip Webb f676602c96 Merge branch '2.5.x' into 2.6.x 3 years ago
Phillip Webb 783981ba98 Merge branch '2.4.x' into 2.5.x 3 years ago
Phillip Webb d336a96b7f Update web.xml xsd references to for 3.1 version
See gh-29075
3 years ago
Phillip Webb a74b563b49 Merge branch '2.6.x' into 2.7.x 3 years ago
Phillip Webb a6a5b81dd0 Merge branch '2.5.x' into 2.6.x 3 years ago
Phillip Webb f3bcbca841 Update copyright year of changed files 3 years ago
Scott Frederick 4cad4851da Merge branch '2.6.x' into 2.7.x
Closes gh-29088
3 years ago
Scott Frederick 92b096abbf Fix message interpolation when code is used as default message
When `setUseCodeAsDefaultMessage(true)` was set on a message source,
attempting to interpolate the default message returned from the message
source would result in the code being unusable by upstream message
resolvers.

Fixes gh-28930
3 years ago
Stephane Nicoll 3039272a70 Merge branch '2.6.x' into 2.7.x 3 years ago
Stephane Nicoll 6555ad404e Merge branch '2.5.x' into 2.6.x 3 years ago
Stephane Nicoll f2efe56a18 Upgrade to Spring Framework 5.3.14 3 years ago
Stephane Nicoll a7a37f4ad6 Upgrade to Spring Framework 5.3.14
Closes gh-28970
3 years ago
Stephane Nicoll b8bf2cbbc7 Upgrade to Spring Framework 5.3.14
Closes gh-28961
3 years ago
Stephane Nicoll 63427b77d1 Merge branch '2.6.x' into 2.7.x
Closes gh-29086
3 years ago
Stephane Nicoll 55859ea64c Stop accessing the datasource if initialization mode is set to never
Closes gh-28931
3 years ago
Phillip Webb b85b6b06a6 Merge branch '2.6.x' into 2.7.x
Closes gh-29078
3 years ago
Phillip Webb 6e01c3edbe Merge branch '2.5.x' into 2.6.x
Closes gh-29077
3 years ago
Phillip Webb 17363d1b3a Merge branch '2.4.x' into 2.5.x
Closes gh-29076
3 years ago
Phillip Webb 1749c893dc Update web-app version to 3.1
Update the web-app version specified in `web.xml` to 3.1 in order to
make Eclipse happy.

Closes gh-29075
3 years ago
Scott Frederick a773af0387 Merge branch '2.6.x' into 2.7.x
Closes gh-29073
3 years ago
Scott Frederick 9e6709eda0 Enable caching for system tests in CI
Setting the `systemTest` Gradle task output as never up-to-date ensures
that all system tests are executed each time they are run in CI. The
`--rerun-tasks` Gradle option that was used previously had the same
effect but also disabled build caching.

Closes gh-29029
3 years ago
Stephane Nicoll 4b1c0e5a03 Start building against Spring Framework 5.3.14 snapshots 3 years ago
Stephane Nicoll 38aeeee381 Merge branch '2.6.x' into 2.7.x 3 years ago
Stephane Nicoll 3b4d27e4d3 Merge branch '2.5.x' into 2.6.x 3 years ago
Stephane Nicoll 30ebb17b2b Polish 3 years ago