spring-security
https://github.com/spring-projects/spring-security
Java
Spring Security
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Java not yet supported214 Subscribers
View all SubscribersAdd a CodeTriage badge to spring-security
Help out
- Issues
- Add OpenFGA Support
- Consider adding dependency convergence detection
- `EnableWebSocketSecurity` is not 1:1 replacement for `AbstractSecurityWebSocketMessageBrokerConfigurer`
- Calling SecurityContextHolder.setStrategyName(strategy) breaks Spring filters
- Improve CVE-2023-34035 detection
- Provide Micrometer Context Propagation for SecurityContext
- Add request to Observation Context at creation to enable filtering by the request
- Provide a way for OAuth2 Resource server to cache the given tokens during the token lifetime
- HttpSecurity bean has no option to disable defaults
- Consider adding support for pushed authorization requests (PAR, RFC 9126)
- Docs
- Java not yet supported