-
Notifications
You must be signed in to change notification settings - Fork 6k
Issues: spring-projects/spring-security
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Remove deprecated implementations of OAuth2AccessTokenResponseClient
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove HandlerMappingIntrospector Usage
type: breaks-passivity
A change that breaks passivity with the previous release
type: task
A general task
type: theme
An issue that describes a theme for a release
ServerCsrfTokenRequestHandler should return reactive types
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Consider making UserInfo request opt-in instead of default in Spring Security 7
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Favor Relative Redirects by Default
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Leave Filter Chain Observations Off By Default
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Consider favoring ObjectProvider#getIfAvailable
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Consider removing generics from An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
AuthorizationRequestRepository
in: oauth2
Consider Signing Metadata by Default
in: saml2
An issue in SAML2 modules
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
authorizeRequests
from Kotlin DSL
in: config
Should OidcIdToken implement equals?
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Improve JdbcUserDetailsManager.userExists method
in: core
An issue in spring-security-core
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove deprecated methods from CookieServerCsrfTokenRepository
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove deprecations from CookieCsrfTokenRepository
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove ApacheDS
in: ldap
An issue in spring-security-ldap
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Default Servlet Headers Should Include Referrer-Policy
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Remove AbstractConfiguredSecurityBuilder#apply
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Consider removing underused modules and APIs
theme: partner-use-cases
Use cases we identified with a partner (an established contributor)
type: breaks-passivity
A change that breaks passivity with the previous release
#13272
opened Jun 2, 2023 by
jgrandja
Consider removing XML configuration support
theme: partner-use-cases
Use cases we identified with a partner (an established contributor)
type: breaks-passivity
A change that breaks passivity with the previous release
#13271
opened Jun 2, 2023 by
jgrandja
Remove LazyCsrfTokenRepository
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
#13196
opened May 18, 2023 by
jzheaux
Align Return Types of no-arg and Customizer arg Configuration Methods
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
#13093
opened Apr 25, 2023 by
marcusdacoregio
Make DefaultRequestRejectedHandler Return HTTP 400 by default
in: web
An issue in web modules (web, webmvc)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
#13081
opened Apr 24, 2023 by
NathanD001
Remove .and() and non lambda methods from DSL
in: config
An issue in spring-security-config
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Saml2LogoutRequest constructor should check for null values
in: saml2
An issue in SAML2 modules
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
#12775
opened Feb 23, 2023 by
marcusdacoregio
Remove ApacheDSContainer and related support
in: ldap
An issue in spring-security-ldap
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Previous Next
ProTip!
What’s not been updated in a month: updated:<2025-03-19.