-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Pull requests: spring-projects/spring-security
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Bump org.springframework.data:spring-data-bom from 2024.1.7 to 2024.1.8
type: dependency-upgrade
A dependency upgrade
#17642
opened Jul 31, 2025 by
dependabot
bot
Loading…
Add Referrer-Policy header to default security headers
status: waiting-for-triage
An issue we've not yet triaged
#17606
opened Jul 23, 2025 by
therepanic
Loading…
Remove PortResolver
status: waiting-for-triage
An issue we've not yet triaged
#17524
opened Jul 14, 2025 by
kse-music
Loading…
Add An issue in spring-security-core
type: enhancement
A general enhancement
createdTime
field to SessionInformation
in: core
#17513
opened Jul 13, 2025 by
therepanic
Loading…
PKCE configuration - enabled by default
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
#17507
opened Jul 10, 2025 by
rohan-naik07
Loading…
Add lambda DSL method for featurePolicy
status: waiting-for-triage
An issue we've not yet triaged
#17492
opened Jul 7, 2025 by
therepanic
Loading…
Implement equals and hashCode in An issue we've not yet triaged
OidcIdToken
status: waiting-for-triage
#17485
opened Jul 4, 2025 by
therepanic
Loading…
Remove ACL access implementations in favor of An issue in spring-security-acl
status: blocked
An issue that's blocked on an external project change
type: breaks-passivity
A change that breaks passivity with the previous release
AclPermissionEvaluator
in: acl
#17475
opened Jul 3, 2025 by
therepanic
Loading…
Add ExpressionTemplateValueProvider
in: core
An issue in spring-security-core
status: feedback-provided
Feedback has been provided
type: enhancement
A general enhancement
Change An issue we've not yet triaged
FilterBasedLdapUserSearch
to use LdapClient
status: waiting-for-triage
#17384
opened Jun 29, 2025 by
therepanic
Loading…
Allow specifying a ServerAuthenticationConverter for x509()
status: waiting-for-triage
An issue we've not yet triaged
#17382
opened Jun 27, 2025 by
blake-bauman
Loading…
Allow multiple ServerLogoutHandler instances in ServerHttpSecurity
in: config
An issue in spring-security-config
type: enhancement
A general enhancement
Remove An issue we've not yet triaged
AllowFromStrategy
in favor of ContentSecurityPolicy
status: waiting-for-triage
#17358
opened Jun 25, 2025 by
therepanic
Loading…
Convert to use LdapClient instead of SpringSecurityLdapTemplate in Pa…
status: waiting-for-triage
An issue we've not yet triaged
#17324
opened Jun 21, 2025 by
minkukjo
Loading…
Adjust log message to include guidance for XML users
status: waiting-for-triage
An issue we've not yet triaged
#17317
opened Jun 20, 2025 by
x7Git
Loading…
Improve authoritiesClaimName validation in JwtGrantedAuthoritiesConverter
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#17247
opened Jun 14, 2025 by
chanbinme
Loading…
Ensure ID Token is updated after refresh token (Reactive)
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Fix PublicKeyCredentialType.PUBLIC_KEY comparison with Spring Session
in: web
An issue in web modules (web, webmvc)
status: feedback-provided
Feedback has been provided
type: bug
A general bug
#17223
opened Jun 10, 2025 by
ltanguy
Loading…
Add Support DPoP Customization
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Support custom An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
OAuth2AuthenticatedPrincipal
in Jwt-based authentication flow
in: oauth2
#17191
opened Jun 1, 2025 by
therepanic
Loading…
Make X509CertificateThumbprintValidator to be public and non-final class
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#17178
opened May 28, 2025 by
edmundham
Loading…
Add support setting X509PrincipalExtractor as bean
status: waiting-for-triage
An issue we've not yet triaged
#17171
opened May 26, 2025 by
franticticktick
Loading…
Add option to disable anonymous authentication in A general enhancement
RSocketSecurity
in: rsocket
type: enhancement
Fix traceId discrepancy in case error in servlet web
in: web
An issue in web modules (web, webmvc)
status: feedback-provided
Feedback has been provided
type: bug
A general bug
Document Upgrading Password Encoding
status: waiting-for-triage
An issue we've not yet triaged
#17120
opened May 15, 2025 by
m0rk4
Loading…
Previous Next
ProTip!
Updated in the last three days: updated:>2025-07-28.