-
Notifications
You must be signed in to change notification settings - Fork 6k
Issues: spring-projects/spring-security
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
ServerCsrfTokenRequestHandler should return reactive types
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Spring Security and Error Handling
in: web
An issue in web modules (web, webmvc)
type: bug
A general bug
Replace WebInvocationPrivilegeEvaluator
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
#16543
opened Feb 5, 2025 by
jzheaux
3 tasks
AbstractUserDetailsAuthenticationProvider should not swallow UsernameNotFoundException
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
#16496
opened Jan 28, 2025 by
jzheaux
AntPathRequestMatcher and MvcRequestMatcher have inconsistent behaviour against requests with null method
in: web
An issue in web modules (web, webmvc)
type: bug
A general bug
#16491
opened Jan 27, 2025 by
symposion
One Time Token should not be created if user does not exist
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
#16483
opened Jan 24, 2025 by
rwinch
5 of 6 tasks
Support for WebAuthn Registration for anonymous user
in: web
An issue in web modules (web, webmvc)
status: feedback-provided
Feedback has been provided
type: enhancement
A general enhancement
#16351
opened Dec 30, 2024 by
justincranford
Favor Relative Redirects by Default
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Improve the BasicAuthenticationFilter to allow callbacks for both successful and failed authentication events.
in: web
An issue in web modules (web, webmvc)
status: feedback-provided
Feedback has been provided
type: enhancement
A general enhancement
#16281
opened Dec 13, 2024 by
pongdangx2
Add @AuthorizeRequestMapping annotation
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
Add "Best Match" based Web Authorization Rules
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
Simplify Custom Handling for Compromised Passwords
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
Passkey Endpoints do not Honor .permitAll()
in: web
An issue in web modules (web, webmvc)
status: feedback-provided
Feedback has been provided
type: bug
A general bug
#16070
opened Nov 12, 2024 by
Jyosua
Improve Integration between Authorized Objects and Spring MVC
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
Remove PortResolver
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
Support Reactive One-Time Tokens in a Clustered Environment
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
Consider allowing An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
oneTimeTokenLogin()
to authenticate different devices
in: web
#15744
opened Sep 5, 2024 by
marcusdacoregio
Consider a An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
OneTimeToken
integration with Spring MVC
in: web
#15623
opened Aug 16, 2024 by
marcusdacoregio
Spring Webflex - reactor core exception - accessing endpoint with http: basic auth
in: web
An issue in web modules (web, webmvc)
status: feedback-provided
Feedback has been provided
#15348
opened Jul 2, 2024 by
dreamstar-enterprises
@EnableReactiveMethodSecurity does not support ResponseEntity<Publisher<T>> as return type
in: web
An issue in web modules (web, webmvc)
status: blocked
An issue that's blocked on an external project change
type: enhancement
A general enhancement
#14731
opened Mar 13, 2024 by
elkhart
Consider a An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
ReactiveMaximumSessionExceededHandler
that performs POST /logout
in: web
#14510
opened Jan 30, 2024 by
marcusdacoregio
Improve Single-Sign-On Redirect for SameSite=Lax and SameSite=Strict
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
#14297
opened Dec 13, 2023 by
jzheaux
Simplify CSRF Configuration for SPAs
in: web
An issue in web modules (web, webmvc)
type: enhancement
A general enhancement
#14149
opened Nov 15, 2023 by
jzheaux
Previous Next
ProTip!
Updated in the last three days: updated:>2025-04-15.