spring-security
https://github.com/spring-projects/spring-security
Java
Spring Security
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Java not yet supported201 Subscribers
View all SubscribersAdd a CodeTriage badge to spring-security
Help out
- Issues
- SEC-2614: Document Error Handling for MultipartFilter
- Session authentication strategy is not called after successfully authentication
- SEC-2403: CsrfFilter and CsrfRequestDataValueProcessor is not consistent on policy of injection.
- SEC-3195: Authentication Entry point in case of JS clients ignores authException details
- property permissionEvaluator of DefaultMethodSecurityExpressionHandler is always DenyAllPermissionEvaluator in child application context
- The default initialization vector size of the AesBytesEncryptor should be 12 bytes for GCM
- SEC-2548: AuthenticationSwitchUserEvent is published before the actual Authentication object is placed in SecurityContext
- SEC-3038: Warn of default HSTS header impact in migration docs
- SEC-2655: CsrfFilter could return token as header
- The class with java.sql.Timestamp is not whitelisted.
- Docs
- Java not yet supported