Commit Graph
273 Commits
Author SHA1 Message Date
Josh Cummings 78015d251c Merge branch '7.0.x' 2026-03-20 15:28:44 -06:00
Josh Cummings 956561e143 Merge branch '6.5.x' into 7.0.x 2026-03-20 15:28:36 -06:00
Rob Winch 9fed1ac8c3 New line per sentence
Signed-off-by: Rob Winch <[email protected]>
2026-03-20 15:28:21 -06:00
Josh Cummings 9dbe3bdcc0 Polish Session Management Persistence Docs
Signed-off-by: Josh Cummings <[email protected]>
2026-03-20 15:28:21 -06:00
sankranti d547ae0181 Fix defaults description in Session Management doc
Corrected that starting from Spring Security 6
security context is not automatically saved by default.

Signed-off-by: sankranti <[email protected]>
2026-03-20 15:28:21 -06:00
Robert Winch ea2f2302da Add MultiFactorCondition.WEBAUTHN_REGISTERED
Closes gh-18923
2026-03-17 17:20:58 -05:00
Robert Winch bd7171140e Support Customizer<AdditionalRequiredFactorsBuilder<Object>>>
Closes gh-18922
2026-03-17 17:20:58 -05:00
Robert Winch 28acf62936 AuthorizationManagerFactories.when
Closes gh-18920
2026-03-17 17:20:58 -05:00
Robert Winch d870548596 Merge Fix spring-security-webauthn dependency in passkeys documentation 2026-03-09 14:26:37 -05:00
Robert Winch 26937bf06c Remove unnecessary webauthn4j dependency 2026-03-09 14:25:08 -05:00
Tran Ngoc Nhan 8e8e1a80a9 Add Passkeys webauthn in example
Signed-off-by: Tran Ngoc Nhan <[email protected]>
2026-03-09 14:23:14 -05:00
Tran Ngoc Nhan 89260a3a9c Use reference links from attributes
Signed-off-by: Tran Ngoc Nhan <[email protected]>
2026-03-03 16:51:25 -07:00
Josh Cummings a01c0d003c Merge branch '7.0.x' 2026-03-03 16:44:25 -07:00
Josh Cummings 20a7f96062 Merge branch '6.5.x' into 7.0.x 2026-03-03 16:44:12 -07:00
HaiYan 706b059ea8 Update logout.adoc
Directives should be Directive

Signed-off-by: HaiYan <[email protected]>
2026-03-03 16:43:18 -07:00
Josh Cummings 50caf0cb28 Merge branch '7.0.x' 2026-02-26 15:57:27 -07:00
Tran Ngoc Nhan 7c3c8bbdcb Update Remember-Me example
Closes gh-18639

Signed-off-by: Tran Ngoc Nhan <[email protected]>
2026-02-26 15:28:32 -07:00
Robert Winch e1436c39f0 Merge Document Keberose Dependency Coordinates 2026-02-23 11:33:25 -06:00
busoco-sjb 17b434c1c1 Document the change in dependency coordinates with Spring Security 7
Signed-off-by: busoco-sjb <[email protected]>
2026-02-23 11:21:59 -06:00
Josh Cummings fc2fd63793 Merge branch '7.0.x' 2026-02-05 17:23:08 -07:00
Vincent Stradiot 075c48c0d8 Fix typo in documentation
Signed-off-by: Vincent Stradiot <[email protected]>
2026-02-05 17:22:43 -07:00
Josh Cummings 30d6b3a02b Merge branch '7.0.x' 2026-01-15 12:41:29 -07:00
Josh Cummings 1f39a3dd3e Merge branch '6.5.x' into 7.0.x 2026-01-15 12:41:22 -07:00
Josh Cummings 84b124d29d Merge branch '6.4.x' into 6.5.x 2026-01-15 12:41:16 -07:00
songhee fee6a9bb0e docs: add CurrentSecurityContext section and link references
Signed-off-by: songhee <[email protected]>
2026-01-15 12:31:58 -07:00
Tran Ngoc Nhan cfe13c7c76 Fix typos
Signed-off-by: Tran Ngoc Nhan <[email protected]>
2026-01-15 10:52:01 -07:00
Robert Winch 2344fe5ebb Use proper xref syntax
Incldue the required resource id and required # of the fragment.

See

- https://docs.antora.org/antora/latest/page/xref/#xref-macro
- https://docs.antora.org/antora/latest/page/resource-id-coordinates/#id-resource
2026-01-09 09:21:02 -06:00
Tran Ngoc Nhan ba18f681e5 Use xref anchor id
Signed-off-by: Tran Ngoc Nhan <[email protected]>
2026-01-09 09:21:02 -06:00
Tran Ngoc Nhan 3d9bc6a5cf Update mfa.adoc
Signed-off-by: Tran Ngoc Nhan <[email protected]>
2026-01-09 09:21:02 -06:00
Martin Boulais 1d8ea63a9e Fix typo in HTTP Basic Auth Provider documentation
The documentation states that setting the header `X-Requested-By` will remove the `WWW-Authenticate` header from the response.
However, after testing this and reading the library code it looks like the header to set is `X-Requested-With` (X-Requested-By is mentioned nowhere except in this documentation file), so I propose this simple PR to fix this.

Signed-off-by: Martin Boulais <[email protected]>
2026-01-08 13:59:34 -06:00
Peter Potrowl d84d0ca22e Fix typo in ldap.adoc
Signed-off-by: Peter Potrowl <[email protected]>
2025-11-21 10:33:48 -06:00
Peter Potrowl f1793f5047 Fix typo in passkeys.adoc
Signed-off-by: Peter Potrowl <[email protected]>
2025-11-21 10:33:48 -06:00
Peter Potrowl 4b227649f0 Fix typo in ldap.adoc
Signed-off-by: Peter Potrowl <[email protected]>
2025-11-21 10:28:47 -06:00
Peter Potrowl cfc27f8cc3 Fix typo in passkeys.adoc
Signed-off-by: Peter Potrowl <[email protected]>
2025-11-21 10:28:47 -06:00
Peter Potrowl 5baff27ffb Fix typo in ldap.adoc
Signed-off-by: Peter Potrowl <[email protected]>
2025-11-21 10:12:20 -06:00
Peter Potrowl 39aaf25b60 Fix typo in passkeys.adoc
Signed-off-by: Peter Potrowl <[email protected]>
2025-11-21 10:12:20 -06:00
Rob Winch 6471a32d66 Merge branch '6.5.x'
Closes gh-18132
2025-11-04 11:37:11 -06:00
Rob Winch c1e9e10bf0 Merge branch '6.4.x' into 6.5.x
Closes gh-18131
2025-11-04 11:28:40 -06:00
Daniel Garnier-Moiroux fed6df5167 Default WebAuthnConfigurer#rpName to rpId
In WebAuthn L3 spec, PublicKeyCredentialEntity.name is deprecated:

> This member is deprecated because many clients do not display it,
> but it remains a required dictionary member for backwards compatibility.
> Relying Parties MAY, as a safe default, set this equal to the RP ID.

Source: https://www.w3.org/TR/webauthn-3/#dictdef-publickeycredentialentity

Signed-off-by: Daniel Garnier-Moiroux <[email protected]>
2025-11-04 11:16:22 -06:00
Rob Winch 884cf0d62e EnableGlobalMultiFactorAuthentication->EnableMultiFactorAuthentication
Closes gh-18127
2025-11-03 22:42:28 -06:00
Rob Winch 78701f94ee Document RequiredFactor Valid Duration
Issue gh-17997
2025-10-10 16:24:47 -05:00
Rob Winch 702878acae Create AuthorizationManagerFactories.multiFactor
Closes gh-18032
2025-10-10 16:24:47 -05:00
Rob Winch d18431a78d Move FACTOR_ constants to FactorGrantedAuthority
Previously GrantedAuthorities had an implicit package tangle because it
was located in ~.core and FactorGrantedAuthority is in ~.core.authority
and FactorGrantedAuthority's authority property was implicitly expected
to be constants found in `GrantedAuthorities`.

This commit moves the constants to the FactorGrantedAuthority which
resolves this tangle. It wasn't initially done because
FactorGrantedAuthority did not exist at that time.

Closes gh-18030
2025-10-10 16:24:46 -05:00
Rob Winch e290c98e97 Document Multi-Factor Simple to Complex
This reworks the Multi-Factor documentation to start with the
simplest scenario and work to progressively more complex requirements.

Closes gh-18029
2025-10-10 16:23:38 -05:00
Rob Winch f652920bb3 Add @EnableGlobalMultiFactorAuthentication
Closes gh-17954
2025-09-24 14:47:26 -05:00
Josh Cummings bbba2930e9 Add Initial Documentation
Issue gh-17934
2025-09-23 18:16:36 -06:00
Josh Cummings 1e1cb0097a Document Authentication Factors
Issue gh-17933
2025-09-19 11:32:28 -06:00
Rob Winch 1b263cfafb Fix Keberos Docs http://
Issue gh-17879
2025-09-12 14:39:46 -05:00
Rob Winch f5fb127c8c Add Spring Security Kerberos
Move the Spring Security Kerberos Extension into Spring Security

Closes gh-17879
2025-09-12 14:25:20 -05:00
Josh Cummings b09afb34cc Document Authentication.Builder
The commit documents the new Authentication Builder interface
and its usage in the security filter chain.

Closes gh-17861
Closes gh-17862
2025-09-09 14:59:14 -06:00