Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e3e7d76b70 |
@@ -1,7 +0,0 @@
|
|||||||
name: Build Release
|
|
||||||
runs:
|
|
||||||
using: composite
|
|
||||||
steps:
|
|
||||||
- name: Build Release
|
|
||||||
shell: bash
|
|
||||||
run: ./gradlew -PdeploymentRepository=$(pwd)/deployment-repository publishAllPublicationsToDeploymentRepository
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
name: Test Release
|
|
||||||
runs:
|
|
||||||
using: composite
|
|
||||||
steps:
|
|
||||||
- name: Test Release
|
|
||||||
shell: bash
|
|
||||||
run: ./gradlew build
|
|
||||||
+42
-129
@@ -1,13 +1,14 @@
|
|||||||
version: 2
|
version: 2
|
||||||
registries:
|
registries:
|
||||||
|
spring-milestones:
|
||||||
|
type: maven-repository
|
||||||
|
url: https://repo.spring.io/milestone
|
||||||
shibboleth:
|
shibboleth:
|
||||||
type: maven-repository
|
type: maven-repository
|
||||||
url: https://build.shibboleth.net/maven/releases
|
url: https://build.shibboleth.net/maven/releases
|
||||||
updates:
|
updates:
|
||||||
|
|
||||||
# 7.0.x
|
|
||||||
- package-ecosystem: gradle
|
- package-ecosystem: gradle
|
||||||
target-branch: 7.0.x
|
target-branch: 6.5.x
|
||||||
directory: /
|
directory: /
|
||||||
schedule:
|
schedule:
|
||||||
interval: daily
|
interval: daily
|
||||||
@@ -15,60 +16,8 @@ updates:
|
|||||||
timezone: Etc/UTC
|
timezone: Etc/UTC
|
||||||
labels:
|
labels:
|
||||||
- 'type: dependency-upgrade'
|
- 'type: dependency-upgrade'
|
||||||
- 'in: build'
|
|
||||||
registries:
|
|
||||||
- shibboleth
|
|
||||||
ignore:
|
|
||||||
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
|
||||||
- dependency-name: io.spring.nullability:*
|
|
||||||
- dependency-name: org.python:jython
|
|
||||||
- dependency-name: org.apache.directory.server:*
|
|
||||||
- dependency-name: org.apache.directory.shared:*
|
|
||||||
- dependency-name: org.junit:junit-bom
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- dependency-name: org.mockito:mockito-bom
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- dependency-name: com.gradle.enterprise
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- version-update:semver-minor
|
|
||||||
- dependency-name: '*'
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- version-update:semver-minor
|
|
||||||
- package-ecosystem: npm
|
|
||||||
target-branch: 7.0.x
|
|
||||||
directory: /docs
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
labels:
|
|
||||||
- 'type: task'
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
target-branch: 7.0.x
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
labels:
|
|
||||||
- 'type: task'
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
|
||||||
|
|
||||||
# 7.1.x
|
|
||||||
- package-ecosystem: gradle
|
|
||||||
target-branch: 7.1.x
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: daily
|
|
||||||
time: '03:00'
|
|
||||||
timezone: Etc/UTC
|
|
||||||
labels:
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
|
||||||
registries:
|
registries:
|
||||||
|
- spring-milestones
|
||||||
- shibboleth
|
- shibboleth
|
||||||
ignore:
|
ignore:
|
||||||
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
||||||
@@ -81,34 +30,38 @@ updates:
|
|||||||
- dependency-name: org.mockito:mockito-bom
|
- dependency-name: org.mockito:mockito-bom
|
||||||
update-types:
|
update-types:
|
||||||
- version-update:semver-major
|
- version-update:semver-major
|
||||||
- dependency-name: com.gradle.enterprise
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- version-update:semver-minor
|
|
||||||
- dependency-name: '*'
|
- dependency-name: '*'
|
||||||
update-types:
|
update-types:
|
||||||
- version-update:semver-major
|
- version-update:semver-major
|
||||||
- version-update:semver-minor
|
- version-update:semver-minor
|
||||||
- package-ecosystem: npm
|
- package-ecosystem: gradle
|
||||||
target-branch: 7.1.x
|
target-branch: 6.4.x
|
||||||
directory: /docs
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
labels:
|
|
||||||
- 'type: task'
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
target-branch: 7.1.x
|
|
||||||
directory: /
|
directory: /
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: daily
|
||||||
|
time: '03:00'
|
||||||
|
timezone: Etc/UTC
|
||||||
labels:
|
labels:
|
||||||
- 'type: task'
|
|
||||||
- 'type: dependency-upgrade'
|
- 'type: dependency-upgrade'
|
||||||
- 'in: build'
|
registries:
|
||||||
|
- spring-milestones
|
||||||
|
- shibboleth
|
||||||
|
ignore:
|
||||||
|
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
||||||
|
- dependency-name: org.python:jython
|
||||||
|
- dependency-name: org.apache.directory.server:*
|
||||||
|
- dependency-name: org.apache.directory.shared:*
|
||||||
|
- dependency-name: org.junit:junit-bom
|
||||||
|
update-types:
|
||||||
|
- version-update:semver-major
|
||||||
|
- dependency-name: org.mockito:mockito-bom
|
||||||
|
update-types:
|
||||||
|
- version-update:semver-major
|
||||||
|
- dependency-name: '*'
|
||||||
|
update-types:
|
||||||
|
- version-update:semver-major
|
||||||
|
- version-update:semver-minor
|
||||||
|
|
||||||
# main
|
|
||||||
- package-ecosystem: gradle
|
- package-ecosystem: gradle
|
||||||
target-branch: main
|
target-branch: main
|
||||||
directory: /
|
directory: /
|
||||||
@@ -118,8 +71,8 @@ updates:
|
|||||||
timezone: Etc/UTC
|
timezone: Etc/UTC
|
||||||
labels:
|
labels:
|
||||||
- 'type: dependency-upgrade'
|
- 'type: dependency-upgrade'
|
||||||
- 'in: build'
|
|
||||||
registries:
|
registries:
|
||||||
|
- spring-milestones
|
||||||
- shibboleth
|
- shibboleth
|
||||||
ignore:
|
ignore:
|
||||||
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
||||||
@@ -139,6 +92,17 @@ updates:
|
|||||||
- dependency-name: '*'
|
- dependency-name: '*'
|
||||||
update-types:
|
update-types:
|
||||||
- version-update:semver-major
|
- version-update:semver-major
|
||||||
|
- version-update:semver-minor
|
||||||
|
|
||||||
|
- package-ecosystem: npm
|
||||||
|
target-branch: docs-build
|
||||||
|
directory: /
|
||||||
|
schedule:
|
||||||
|
interval: weekly
|
||||||
|
labels:
|
||||||
|
- 'type: task'
|
||||||
|
- 'in: build'
|
||||||
|
|
||||||
- package-ecosystem: npm
|
- package-ecosystem: npm
|
||||||
target-branch: main
|
target-branch: main
|
||||||
directory: /docs
|
directory: /docs
|
||||||
@@ -146,63 +110,12 @@ updates:
|
|||||||
interval: weekly
|
interval: weekly
|
||||||
labels:
|
labels:
|
||||||
- 'type: task'
|
- 'type: task'
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
- 'in: build'
|
||||||
- package-ecosystem: github-actions
|
|
||||||
target-branch: main
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
labels:
|
|
||||||
- 'type: task'
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
|
||||||
|
|
||||||
# docs-build
|
|
||||||
- package-ecosystem: gradle
|
|
||||||
target-branch: docs-build
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: daily
|
|
||||||
time: '03:00'
|
|
||||||
timezone: Etc/UTC
|
|
||||||
labels:
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
registries:
|
|
||||||
- shibboleth
|
|
||||||
ignore:
|
|
||||||
- dependency-name: com.nimbusds:nimbus-jose-jwt
|
|
||||||
- dependency-name: org.python:jython
|
|
||||||
- dependency-name: org.apache.directory.server:*
|
|
||||||
- dependency-name: org.apache.directory.shared:*
|
|
||||||
- dependency-name: org.junit:junit-bom
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- dependency-name: org.mockito:mockito-bom
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- dependency-name: com.gradle.enterprise
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- version-update:semver-minor
|
|
||||||
- dependency-name: '*'
|
|
||||||
update-types:
|
|
||||||
- version-update:semver-major
|
|
||||||
- package-ecosystem: npm
|
- package-ecosystem: npm
|
||||||
target-branch: docs-build
|
target-branch: 6.3.x
|
||||||
directory: /
|
directory: /docs
|
||||||
schedule:
|
schedule:
|
||||||
interval: weekly
|
interval: weekly
|
||||||
labels:
|
labels:
|
||||||
- 'type: task'
|
- 'type: task'
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
target-branch: docs-build
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
labels:
|
|
||||||
- 'type: task'
|
|
||||||
- 'type: dependency-upgrade'
|
|
||||||
- 'in: build'
|
- 'in: build'
|
||||||
|
|||||||
@@ -1,17 +0,0 @@
|
|||||||
workflow:
|
|
||||||
generator:
|
|
||||||
project:
|
|
||||||
java:
|
|
||||||
versions:
|
|
||||||
primary: 25
|
|
||||||
workflows:
|
|
||||||
release-train:
|
|
||||||
build:
|
|
||||||
env:
|
|
||||||
COMMERCIAL_REPO_USERNAME: secrets.COMMERCIAL_ARTIFACTORY_USERNAME
|
|
||||||
COMMERCIAL_REPO_PASSWORD: secrets.COMMERCIAL_ARTIFACTORY_PASSWORD
|
|
||||||
test:
|
|
||||||
env:
|
|
||||||
COMMERCIAL_REPO_USERNAME: secrets.COMMERCIAL_ARTIFACTORY_USERNAME
|
|
||||||
COMMERCIAL_REPO_PASSWORD: secrets.COMMERCIAL_ARTIFACTORY_PASSWORD
|
|
||||||
|
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
name: CI
|
||||||
|
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: '0 10 * * *' # Once per day at 10am UTC
|
||||||
|
workflow_dispatch: # Manual trigger
|
||||||
|
|
||||||
|
env:
|
||||||
|
DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
snapshot-test:
|
||||||
|
name: Test Against Snapshots
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/workflows/test.yml@v1
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- java-version: 21-ea
|
||||||
|
toolchain: 21
|
||||||
|
- java-version: 17
|
||||||
|
toolchain: 17
|
||||||
|
with:
|
||||||
|
java-version: ${{ matrix.java-version }}
|
||||||
|
test-args: --refresh-dependencies -PforceMavenRepositories=snapshot,https://oss.sonatype.org/content/repositories/snapshots -PisOverrideVersionCatalog -PtestToolchain=${{ matrix.toolchain }} -PspringFrameworkVersion=7.+ -PreactorVersion=2025.+ -PspringDataVersion=2025.+ --stacktrace
|
||||||
|
secrets: inherit
|
||||||
|
send-notification:
|
||||||
|
name: Send Notification
|
||||||
|
needs: [ snapshot-test ]
|
||||||
|
if: ${{ !success() }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Send Notification
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
||||||
|
with:
|
||||||
|
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
name: Clean build artifacts
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: '0 10 * * *' # Once per day at 10am UTC
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
main:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
if: ${{ github.repository == 'spring-projects/spring-security' }}
|
||||||
|
permissions:
|
||||||
|
contents: none
|
||||||
|
steps:
|
||||||
|
- name: Delete artifacts in cron job
|
||||||
|
env:
|
||||||
|
GH_ACTIONS_REPO_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }}
|
||||||
|
run: |
|
||||||
|
echo "Running clean build artifacts logic"
|
||||||
|
output=$(curl -X GET -H "Authorization: token $GH_ACTIONS_REPO_TOKEN" https://api.github.com/repos/spring-projects/spring-security/actions/artifacts | grep '"id"' | cut -d : -f2 | sed 's/,*$//g')
|
||||||
|
echo Output is $output
|
||||||
|
for id in $output; do curl -X DELETE -H "Authorization: token $GH_ACTIONS_REPO_TOKEN" https://api.github.com/repos/spring-projects/spring-security/actions/artifacts/$id; done;
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
name: "CodeQL Advanced"
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
pull_request:
|
||||||
|
workflow_dispatch:
|
||||||
|
schedule:
|
||||||
|
# https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule
|
||||||
|
- cron: '0 5 * * *'
|
||||||
|
permissions: read-all
|
||||||
|
jobs:
|
||||||
|
codeql-analysis-call:
|
||||||
|
permissions:
|
||||||
|
actions: read
|
||||||
|
contents: read
|
||||||
|
security-events: write
|
||||||
|
uses: spring-io/github-actions/.github/workflows/codeql-analysis.yml@1
|
||||||
@@ -8,46 +8,66 @@ on:
|
|||||||
- cron: '0 10 * * *' # Once per day at 10am UTC
|
- cron: '0 10 * * *' # Once per day at 10am UTC
|
||||||
workflow_dispatch: # Manual trigger
|
workflow_dispatch: # Manual trigger
|
||||||
|
|
||||||
|
env:
|
||||||
|
DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
uses: spring-projects/spring-security-commercial/.github/workflows/build.yml@workflows/v1
|
uses: spring-io/spring-security-release-tools/.github/workflows/build.yml@v1
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
os: [ ubuntu-latest, windows-latest ]
|
||||||
|
jdk: [ 17 ]
|
||||||
with:
|
with:
|
||||||
java-version: '25'
|
runs-on: ${{ matrix.os }}
|
||||||
|
java-version: ${{ matrix.jdk }}
|
||||||
|
distribution: temurin
|
||||||
secrets: inherit
|
secrets: inherit
|
||||||
test:
|
|
||||||
name: Test Against Snapshots
|
|
||||||
uses: spring-projects/spring-security-commercial/.github/workflows/test.yml@workflows/v1
|
|
||||||
with:
|
|
||||||
java-version: '25'
|
|
||||||
test-args: --refresh-dependencies -PforceMavenRepositories=snapshot -PisOverrideVersionCatalog -PtestToolchain=25 -PspringFrameworkVersion=7.0.+ -PreactorVersion=2025.0.+ -PspringDataVersion=2026.0.+ -PmicrometerVersion=1.17.+ --stacktrace
|
|
||||||
secrets: inherit
|
|
||||||
compute-version:
|
|
||||||
name: Compute Version
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
outputs:
|
|
||||||
snapshot: ${{ steps.project-version.outputs.snapshot }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # 7.0.0
|
|
||||||
- id: project-version
|
|
||||||
name: Extract Project Version
|
|
||||||
uses: spring-io/spring-release-actions/compute-version@a1f321783a0769dd2aea4fad6c2ae2f95a52b885 # 0.0.5
|
|
||||||
deploy-artifacts:
|
deploy-artifacts:
|
||||||
name: Deploy Artifacts
|
name: Deploy Artifacts
|
||||||
needs: [ build, test, compute-version ]
|
needs: [ build]
|
||||||
if: needs.compute-version.outputs.snapshot == 'true'
|
uses: spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml@v1
|
||||||
uses: spring-projects/spring-security-commercial/.github/workflows/deploy-artifacts.yml@workflows/v1
|
with:
|
||||||
|
should-deploy-artifacts: ${{ needs.build.outputs.should-deploy-artifacts }}
|
||||||
|
default-publish-milestones-central: true
|
||||||
|
secrets: inherit
|
||||||
|
deploy-docs:
|
||||||
|
name: Deploy Docs
|
||||||
|
needs: [ build ]
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/workflows/deploy-docs.yml@v1
|
||||||
|
with:
|
||||||
|
should-deploy-docs: ${{ needs.build.outputs.should-deploy-artifacts }}
|
||||||
|
secrets: inherit
|
||||||
|
deploy-schema:
|
||||||
|
name: Deploy Schema
|
||||||
|
needs: [ build ]
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml@v1
|
||||||
|
with:
|
||||||
|
should-deploy-schema: ${{ needs.build.outputs.should-deploy-artifacts }}
|
||||||
|
secrets: inherit
|
||||||
|
perform-release:
|
||||||
|
name: Perform Release
|
||||||
|
needs: [ deploy-artifacts, deploy-docs, deploy-schema ]
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/workflows/perform-release.yml@v1
|
||||||
|
with:
|
||||||
|
should-perform-release: ${{ needs.deploy-artifacts.outputs.artifacts-deployed }}
|
||||||
|
project-version: ${{ needs.deploy-artifacts.outputs.project-version }}
|
||||||
|
milestone-repo-url: https://repo1.maven.org/maven2
|
||||||
|
release-repo-url: https://repo1.maven.org/maven2
|
||||||
|
artifact-path: org/springframework/security/spring-security-core
|
||||||
|
slack-announcing-id: spring-security-announcing
|
||||||
secrets: inherit
|
secrets: inherit
|
||||||
send-notification:
|
send-notification:
|
||||||
name: Send Notification
|
name: Send Notification
|
||||||
needs: [ deploy-artifacts ]
|
needs: [ perform-release ]
|
||||||
if: ${{ !success() }}
|
if: ${{ !success() }}
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Send Notification
|
- name: Send Notification
|
||||||
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@b92832ecbc7cbe969201e6beafbde0ee400cf095 # v1.0.15
|
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
||||||
with:
|
with:
|
||||||
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
||||||
|
|||||||
@@ -1,10 +0,0 @@
|
|||||||
name: Dependabot PR Build
|
|
||||||
|
|
||||||
on: pull_request_target
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: Build
|
|
||||||
uses: spring-projects/spring-security-commercial/.github/workflows/build-pull-request.yml@workflows/v1
|
|
||||||
if: ${{ github.actor == 'dependabot[bot]' }}
|
|
||||||
secrets: inherit
|
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
name: Deploy Docs
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches-ignore:
|
||||||
|
- "gh-pages"
|
||||||
|
- "dependabot/**"
|
||||||
|
tags: '**'
|
||||||
|
repository_dispatch:
|
||||||
|
types: request-build-reference # legacy
|
||||||
|
#schedule:
|
||||||
|
#- cron: '0 10 * * *' # Once per day at 10am UTC
|
||||||
|
workflow_dispatch:
|
||||||
|
permissions: read-all
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
if: github.repository_owner == 'spring-projects'
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
ref: docs-build
|
||||||
|
fetch-depth: 1
|
||||||
|
- name: Dispatch (partial build)
|
||||||
|
if: github.ref_type == 'branch'
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }}
|
||||||
|
run: gh workflow run deploy-docs.yml -r $(git rev-parse --abbrev-ref HEAD) -f build-refname=${{ github.ref_name }}
|
||||||
|
- name: Dispatch (full build)
|
||||||
|
if: github.ref_type == 'tag'
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }}
|
||||||
|
run: gh workflow run deploy-docs.yml -r $(git rev-parse --abbrev-ref HEAD)
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
name: Finalize Release
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch: # Manual trigger
|
||||||
|
|
||||||
|
env:
|
||||||
|
DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
project-version:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
outputs:
|
||||||
|
version: ${{ steps.project-version.outputs.version }}
|
||||||
|
steps:
|
||||||
|
- id: project-version
|
||||||
|
run: echo "version=$(grep '^version=' gradle.properties | cut -d'=' -f2)" >> $GITHUB_OUTPUT
|
||||||
|
perform-release:
|
||||||
|
name: Perform Release
|
||||||
|
needs: [ project-version ]
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/workflows/perform-release.yml@v1
|
||||||
|
with:
|
||||||
|
should-perform-release: true
|
||||||
|
project-version: ${{ needs.project-version.outputs.version }}
|
||||||
|
milestone-repo-url: https://repo1.maven.org/maven2
|
||||||
|
release-repo-url: https://repo1.maven.org/maven2
|
||||||
|
artifact-path: org/springframework/security/spring-security-core
|
||||||
|
slack-announcing-id: spring-security-announcing
|
||||||
|
secrets: inherit
|
||||||
|
send-notification:
|
||||||
|
name: Send Notification
|
||||||
|
needs: [ perform-release ]
|
||||||
|
if: ${{ !success() }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Send Notification
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
||||||
|
with:
|
||||||
|
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
name: Execute Gradle Wrapper Upgrade
|
||||||
|
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: '0 2 * * *' # 2am UTC
|
||||||
|
workflow_dispatch:
|
||||||
|
permissions:
|
||||||
|
pull-requests: write
|
||||||
|
jobs:
|
||||||
|
upgrade_wrapper:
|
||||||
|
name: Execution
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Set up Git configuration
|
||||||
|
env:
|
||||||
|
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
run: |
|
||||||
|
git config --global url."https://unused-username:${TOKEN}@github.com/".insteadOf "https://github.com/"
|
||||||
|
git config --global user.name 'github-actions[bot]'
|
||||||
|
git config --global user.email 'github-actions[bot]@users.noreply.github.com'
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Set up JDK 17
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
java-version: '17'
|
||||||
|
distribution: 'temurin'
|
||||||
|
- name: Set up Gradle
|
||||||
|
uses: gradle/gradle-build-action@v2
|
||||||
|
- name: Upgrade Wrappers
|
||||||
|
run: ./gradlew clean upgradeGradleWrapperAll --continue -Porg.gradle.java.installations.auto-download=false
|
||||||
|
env:
|
||||||
|
WRAPPER_UPGRADE_GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
@@ -1,63 +0,0 @@
|
|||||||
name: Merge Dependabot PR
|
|
||||||
|
|
||||||
on: pull_request_target
|
|
||||||
|
|
||||||
run-name: Merge Dependabot PR ${{ github.ref_name }}
|
|
||||||
|
|
||||||
permissions: write-all
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
merge-dependabot-pr:
|
|
||||||
name: Merge Dependabot PR
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
if: ${{ github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'spring-projects/spring-security-commercial' }}
|
|
||||||
steps:
|
|
||||||
|
|
||||||
- uses: actions/checkout@v5
|
|
||||||
with:
|
|
||||||
show-progress: false
|
|
||||||
ref: ${{ github.event.pull_request.head.sha }}
|
|
||||||
|
|
||||||
- uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
distribution: temurin
|
|
||||||
java-version: 17
|
|
||||||
|
|
||||||
- name: Set Milestone to Dependabot Pull Request
|
|
||||||
id: set-milestone
|
|
||||||
run: |
|
|
||||||
if test -f pom.xml
|
|
||||||
then
|
|
||||||
CURRENT_VERSION=$(mvn help:evaluate -Dexpression="project.version" -q -DforceStdout)
|
|
||||||
else
|
|
||||||
CURRENT_VERSION=$(cat gradle.properties | sed -n '/^version=/ { s/^version=//;p }')
|
|
||||||
fi
|
|
||||||
export CANDIDATE_VERSION=${CURRENT_VERSION/-SNAPSHOT}
|
|
||||||
MILESTONE=$(gh api repos/$GITHUB_REPOSITORY/milestones --jq 'map(select(.due_on != null and (.title | startswith(env.CANDIDATE_VERSION)))) | .[0] | .title')
|
|
||||||
|
|
||||||
if [ -z $MILESTONE ]
|
|
||||||
then
|
|
||||||
gh run cancel ${{ github.run_id }}
|
|
||||||
echo "::warning title=Cannot merge::No scheduled milestone for $CURRENT_VERSION version"
|
|
||||||
else
|
|
||||||
gh pr edit ${{ github.event.pull_request.number }} --milestone $MILESTONE
|
|
||||||
echo mergeEnabled=true >> $GITHUB_OUTPUT
|
|
||||||
fi
|
|
||||||
env:
|
|
||||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
- name: Merge Dependabot pull request
|
|
||||||
if: steps.set-milestone.outputs.mergeEnabled
|
|
||||||
run: gh pr merge ${{ github.event.pull_request.number }} --auto --rebase
|
|
||||||
env:
|
|
||||||
GH_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }}
|
|
||||||
send-notification:
|
|
||||||
name: Send Notification
|
|
||||||
needs: [ merge-dependabot-pr ]
|
|
||||||
if: ${{ failure() || cancelled() }}
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Send Notification
|
|
||||||
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
|
||||||
with:
|
|
||||||
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
name: Check Milestone
|
||||||
|
on:
|
||||||
|
milestone:
|
||||||
|
types: [created, opened, edited]
|
||||||
|
env:
|
||||||
|
DUE_ON: ${{ github.event.milestone.due_on }}
|
||||||
|
TITLE: ${{ github.event.milestone.title }}
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
jobs:
|
||||||
|
spring-releasetrain-checks:
|
||||||
|
name: Check DueOn is on a Release Date
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
if: ${{ github.repository == 'spring-projects/spring-security' }}
|
||||||
|
permissions:
|
||||||
|
contents: none
|
||||||
|
steps:
|
||||||
|
- name: Print Milestone Being Checked
|
||||||
|
run: echo "Validating DueOn '$DUE_ON' for milestone '$TITLE'"
|
||||||
|
- name: Validate DueOn
|
||||||
|
if: env.DUE_ON != ''
|
||||||
|
run: |
|
||||||
|
export TOOL_VERSION=0.1.1
|
||||||
|
wget "https://repo.maven.apache.org/maven2/io/spring/releasetrain/spring-release-train-tools/$TOOL_VERSION/spring-release-train-tools-$TOOL_VERSION.jar"
|
||||||
|
java -cp "spring-release-train-tools-$TOOL_VERSION.jar" io.spring.releasetrain.CheckMilestoneDueOnMain --dueOn "$DUE_ON" --expectedDayOfWeek MONDAY --expectedMondayCount 3
|
||||||
|
send-notification:
|
||||||
|
name: Send Notification
|
||||||
|
needs: [ spring-releasetrain-checks ]
|
||||||
|
if: ${{ failure() || cancelled() }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Send Notification
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
||||||
|
with:
|
||||||
|
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
||||||
@@ -8,6 +8,44 @@ permissions:
|
|||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build
|
name: Build
|
||||||
uses: spring-projects/spring-security-commercial/.github/workflows/build-pull-request.yml@workflows/v1
|
runs-on: ubuntu-latest
|
||||||
if: ${{ github.actor != 'dependabot[bot]' }}
|
if: ${{ github.repository == 'spring-projects/spring-security' }}
|
||||||
secrets: inherit
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- name: Set up gradle
|
||||||
|
uses: spring-io/spring-gradle-build-action@v2
|
||||||
|
with:
|
||||||
|
java-version: '17'
|
||||||
|
distribution: 'temurin'
|
||||||
|
- name: Build with Gradle
|
||||||
|
run: ./gradlew clean build -PskipCheckExpectedBranchVersion --continue --scan
|
||||||
|
generate-docs:
|
||||||
|
name: Generate Docs
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
if: ${{ github.repository == 'spring-projects/spring-security' }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- name: Set up gradle
|
||||||
|
uses: spring-io/spring-gradle-build-action@v2
|
||||||
|
with:
|
||||||
|
java-version: '17'
|
||||||
|
distribution: 'temurin'
|
||||||
|
- name: Run Antora
|
||||||
|
run: ./gradlew -PbuildSrc.skipTests=true :spring-security-docs:antora
|
||||||
|
- name: Upload Docs
|
||||||
|
id: upload
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: docs
|
||||||
|
path: docs/build/site
|
||||||
|
overwrite: true
|
||||||
|
send-notification:
|
||||||
|
name: Send Notification
|
||||||
|
needs: [ build, generate-docs ]
|
||||||
|
if: ${{ failure() && github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'spring-projects/spring-security' }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Send Notification
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
||||||
|
with:
|
||||||
|
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
name: Release Scheduler
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: '15 15 * * MON' # Every Monday at 3:15pm UTC
|
||||||
|
workflow_dispatch:
|
||||||
|
permissions: read-all
|
||||||
|
jobs:
|
||||||
|
dispatch_scheduled_releases:
|
||||||
|
name: Dispatch scheduled releases
|
||||||
|
if: github.repository_owner == 'spring-projects'
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
# List of active maintenance branches.
|
||||||
|
branch: [ main, 6.5.x, 6.4.x, 6.3.x ]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 1
|
||||||
|
- name: Dispatch
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GH_ACTIONS_REPO_TOKEN }}
|
||||||
|
run: gh workflow run update-scheduled-release-version.yml -r ${{ matrix.branch }}
|
||||||
@@ -1,92 +0,0 @@
|
|||||||
# This file was auto-generated by github-actions-workflow-generator 0.0.6. Do not edit.
|
|
||||||
# To update it, modify .github/workflow-generator.yml as needed and re-run the generator.
|
|
||||||
|
|
||||||
name: "Release Train – Build"
|
|
||||||
run-name: "${{ inputs.callback-ref }} – Build"
|
|
||||||
"on":
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
callback:
|
|
||||||
description: "Repository to which a callback should be made upon completion"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
callback-ref:
|
|
||||||
description: "Ref in the callback repository to which a callback should be made upon completion"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
release-train-maven-repository-url:
|
|
||||||
description: "URL of a Maven repository to be used to resolve artifacts of projects earlier in the train"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
permissions:
|
|
||||||
contents: "read"
|
|
||||||
concurrency:
|
|
||||||
group: "${{ github.workflow }}-${{ github.ref }}"
|
|
||||||
jobs:
|
|
||||||
build-release:
|
|
||||||
name: "Build Release"
|
|
||||||
runs-on: "ubuntu22-2-8"
|
|
||||||
steps:
|
|
||||||
- name: "Prevent Re-runs"
|
|
||||||
id: "prevent-re-runs"
|
|
||||||
run: |-
|
|
||||||
if [ "$GITHUB_RUN_ATTEMPT" -gt 1 ]; then
|
|
||||||
echo "Re-runs are prohibited. Use the 'Release Train – Retry' workflow to retry build failures"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
- name: "Set up Java"
|
|
||||||
id: "set-up-java"
|
|
||||||
uses: "actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95" # v5.6.0
|
|
||||||
with:
|
|
||||||
distribution: "liberica"
|
|
||||||
java-version: "25"
|
|
||||||
- name: "Check Out Code"
|
|
||||||
id: "check-out-code"
|
|
||||||
uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v7.0.0
|
|
||||||
- name: "Build Release"
|
|
||||||
id: "build-release"
|
|
||||||
uses: "./.github/actions/release-train-build"
|
|
||||||
env:
|
|
||||||
COMMERCIAL_REPO_PASSWORD: "${{ secrets.COMMERCIAL_ARTIFACTORY_PASSWORD }}"
|
|
||||||
COMMERCIAL_REPO_USERNAME: "${{ secrets.COMMERCIAL_ARTIFACTORY_USERNAME }}"
|
|
||||||
RELEASE_TRAIN_MAVEN_REPOSITORY_PASSWORD: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_MAVEN_REPOSITORY_PASSWORD }}"
|
|
||||||
RELEASE_TRAIN_MAVEN_REPOSITORY_URL: "${{ inputs.release-train-maven-repository-url }}"
|
|
||||||
RELEASE_TRAIN_MAVEN_REPOSITORY_USERNAME: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_MAVEN_REPOSITORY_USERNAME }}"
|
|
||||||
- name: "Upload Deployment Repository"
|
|
||||||
id: "upload-deployment-repository"
|
|
||||||
uses: "actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a" # v7.0.1
|
|
||||||
with:
|
|
||||||
name: "deployment-repository"
|
|
||||||
path: "deployment-repository/**"
|
|
||||||
- name: "Upload Deployment Spec"
|
|
||||||
id: "upload-deployment-spec"
|
|
||||||
uses: "actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a" # v7.0.1
|
|
||||||
with:
|
|
||||||
archive: "false"
|
|
||||||
if-no-files-found: "ignore"
|
|
||||||
name: "deployment-spec"
|
|
||||||
path: ".github/actions/release-train-build/deployment-spec.yml"
|
|
||||||
- name: "Save Build System Caches"
|
|
||||||
id: "save-build-system-caches"
|
|
||||||
uses: "actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9" # v6.1.0
|
|
||||||
with:
|
|
||||||
key: "release-train-${{ inputs.callback-ref }}-${{ github.ref_name }}"
|
|
||||||
path: |-
|
|
||||||
~/.gradle/caches
|
|
||||||
~/.gradle/wrapper
|
|
||||||
- name: "Send Callback"
|
|
||||||
id: "send-callback"
|
|
||||||
if: "${{ !cancelled() }}"
|
|
||||||
env:
|
|
||||||
GH_TOKEN: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_GITHUB_TOKEN }}"
|
|
||||||
run: |-
|
|
||||||
gh workflow run callback \
|
|
||||||
--repo ${{ inputs.callback }} \
|
|
||||||
--ref ${{ inputs.callback-ref }} \
|
|
||||||
--field commit-hash=${{ steps.check-out-code.outputs.commit }} \
|
|
||||||
--field deployment-repository-artifact-identifier=${{ steps.upload-deployment-repository.outputs.artifact-id }} \
|
|
||||||
--field deployment-spec-artifact-identifier=${{ steps.upload-deployment-spec.outputs.artifact-id }} \
|
|
||||||
--field release-branch=${{ github.ref_name }} \
|
|
||||||
--field release-repository=${{ github.repository }} \
|
|
||||||
--field result=${{ job.status == 'success' && 'built' || 'build-failed' }} \
|
|
||||||
--field workflow-run-url=${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
# This file was auto-generated by github-actions-workflow-generator 0.0.6. Do not edit.
|
|
||||||
# To update it, modify .github/workflow-generator.yml as needed and re-run the generator.
|
|
||||||
|
|
||||||
name: "Release Train – Join"
|
|
||||||
run-name: "${{ inputs.release-train }} – Join"
|
|
||||||
"on":
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
deployment-destination:
|
|
||||||
description: "Destination to which the release should be deployed"
|
|
||||||
options:
|
|
||||||
- "Maven Central"
|
|
||||||
- "Spring Enterprise"
|
|
||||||
required: true
|
|
||||||
type: "choice"
|
|
||||||
release-train:
|
|
||||||
description: "Release train"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
release-train-repository:
|
|
||||||
default: "spring-io/release-train"
|
|
||||||
description: "Release train repository"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
permissions:
|
|
||||||
contents: "none"
|
|
||||||
jobs:
|
|
||||||
join-release-train:
|
|
||||||
name: "Join Release Train"
|
|
||||||
runs-on: "ubuntu-latest"
|
|
||||||
steps:
|
|
||||||
- name: "Join Release Train"
|
|
||||||
id: "join-release-train"
|
|
||||||
env:
|
|
||||||
GH_TOKEN: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_GITHUB_TOKEN }}"
|
|
||||||
run: |-
|
|
||||||
run_url=$(
|
|
||||||
gh workflow run join \
|
|
||||||
--repo ${{ inputs.release-train-repository }} \
|
|
||||||
--ref ${{ inputs.release-train }} \
|
|
||||||
--field commit-hash=${{ github.sha }} \
|
|
||||||
--field deployment-destination=${{ inputs.deployment-destination == 'Maven Central' && 'maven-central' || 'spring-enterprise' }} \
|
|
||||||
--field release-branch=${{ github.ref_name }} \
|
|
||||||
--field release-repository=${{ github.repository }}
|
|
||||||
)
|
|
||||||
echo "Dispatched workflow run. Waiting for $run_url to complete."
|
|
||||||
run_id=${run_url##*/}
|
|
||||||
watch_exit_code=0
|
|
||||||
gh run watch $run_id --repo ${{ inputs.release-train-repository }} --exit-status --interval=3 > /dev/null 2>&1 || watch_exit_code=$?
|
|
||||||
if [[ $watch_exit_code -eq 0 ]]; then
|
|
||||||
echo "Workflow run succeeded."
|
|
||||||
else
|
|
||||||
echo "Workflow run failed."
|
|
||||||
fi
|
|
||||||
exit $watch_exit_code
|
|
||||||
@@ -1,46 +0,0 @@
|
|||||||
# This file was auto-generated by github-actions-workflow-generator 0.0.6. Do not edit.
|
|
||||||
# To update it, modify .github/workflow-generator.yml as needed and re-run the generator.
|
|
||||||
|
|
||||||
name: "Release Train – Leave"
|
|
||||||
run-name: "${{ inputs.release-train }} – Leave"
|
|
||||||
"on":
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
release-train:
|
|
||||||
description: "Release train"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
release-train-repository:
|
|
||||||
default: "spring-io/release-train"
|
|
||||||
description: "Release train repository"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
permissions:
|
|
||||||
contents: "none"
|
|
||||||
jobs:
|
|
||||||
leave:
|
|
||||||
name: "Leave"
|
|
||||||
runs-on: "ubuntu-latest"
|
|
||||||
steps:
|
|
||||||
- name: "Leave"
|
|
||||||
id: "leave"
|
|
||||||
env:
|
|
||||||
GH_TOKEN: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_GITHUB_TOKEN }}"
|
|
||||||
run: |-
|
|
||||||
run_url=$(
|
|
||||||
gh workflow run leave \
|
|
||||||
--repo ${{ inputs.release-train-repository }} \
|
|
||||||
--ref ${{ inputs.release-train }} \
|
|
||||||
--field release-branch=${{ github.ref_name }} \
|
|
||||||
--field release-repository=${{ github.repository }}
|
|
||||||
)
|
|
||||||
echo "Dispatched workflow run. Waiting for $run_url to complete."
|
|
||||||
run_id=${run_url##*/}
|
|
||||||
watch_exit_code=0
|
|
||||||
gh run watch $run_id --repo ${{ inputs.release-train-repository }} --exit-status --interval=3 > /dev/null 2>&1 || watch_exit_code=$?
|
|
||||||
if [[ $watch_exit_code -eq 0 ]]; then
|
|
||||||
echo "Workflow run succeeded."
|
|
||||||
else
|
|
||||||
echo "Workflow run failed."
|
|
||||||
fi
|
|
||||||
exit $watch_exit_code
|
|
||||||
@@ -1,47 +0,0 @@
|
|||||||
# This file was auto-generated by github-actions-workflow-generator 0.0.6. Do not edit.
|
|
||||||
# To update it, modify .github/workflow-generator.yml as needed and re-run the generator.
|
|
||||||
|
|
||||||
name: "Release Train – Ready"
|
|
||||||
run-name: "${{ inputs.release-train }} – Ready"
|
|
||||||
"on":
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
release-train:
|
|
||||||
description: "Release train"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
release-train-repository:
|
|
||||||
default: "spring-io/release-train"
|
|
||||||
description: "Release train repository"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
permissions:
|
|
||||||
contents: "none"
|
|
||||||
jobs:
|
|
||||||
ready:
|
|
||||||
name: "Ready"
|
|
||||||
runs-on: "ubuntu-latest"
|
|
||||||
steps:
|
|
||||||
- name: "Ready"
|
|
||||||
id: "ready"
|
|
||||||
env:
|
|
||||||
GH_TOKEN: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_GITHUB_TOKEN }}"
|
|
||||||
run: |-
|
|
||||||
run_url=$(
|
|
||||||
gh workflow run ready \
|
|
||||||
--repo ${{ inputs.release-train-repository }} \
|
|
||||||
--ref ${{ inputs.release-train }} \
|
|
||||||
--field commit-hash=${{ github.sha }} \
|
|
||||||
--field release-branch=${{ github.ref_name }} \
|
|
||||||
--field release-repository=${{ github.repository }}
|
|
||||||
)
|
|
||||||
echo "Dispatched workflow run. Waiting for $run_url to complete."
|
|
||||||
run_id=${run_url##*/}
|
|
||||||
watch_exit_code=0
|
|
||||||
gh run watch $run_id --repo ${{ inputs.release-train-repository }} --exit-status --interval=3 > /dev/null 2>&1 || watch_exit_code=$?
|
|
||||||
if [[ $watch_exit_code -eq 0 ]]; then
|
|
||||||
echo "Workflow run succeeded."
|
|
||||||
else
|
|
||||||
echo "Workflow run failed."
|
|
||||||
fi
|
|
||||||
exit $watch_exit_code
|
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
# This file was auto-generated by github-actions-workflow-generator 0.0.6. Do not edit.
|
|
||||||
# To update it, modify .github/workflow-generator.yml as needed and re-run the generator.
|
|
||||||
|
|
||||||
name: "Release Train – Retry"
|
|
||||||
run-name: "${{ inputs.release-train }} – Retry"
|
|
||||||
"on":
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
release-train:
|
|
||||||
description: "Release train"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
release-train-repository:
|
|
||||||
default: "spring-io/release-train"
|
|
||||||
description: "Release train repository"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
permissions:
|
|
||||||
contents: "none"
|
|
||||||
jobs:
|
|
||||||
trigger-retry:
|
|
||||||
name: "Trigger Retry"
|
|
||||||
runs-on: "ubuntu-latest"
|
|
||||||
steps:
|
|
||||||
- name: "Trigger Retry"
|
|
||||||
id: "trigger-retry"
|
|
||||||
env:
|
|
||||||
GH_TOKEN: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_GITHUB_TOKEN }}"
|
|
||||||
run: |-
|
|
||||||
gh workflow run retry \
|
|
||||||
--repo ${{ inputs.release-train-repository }} \
|
|
||||||
--ref ${{ inputs.release-train }} \
|
|
||||||
--field release-branch=${{ github.ref_name }} \
|
|
||||||
--field release-repository=${{ github.repository }}
|
|
||||||
@@ -1,83 +0,0 @@
|
|||||||
# This file was auto-generated by github-actions-workflow-generator 0.0.6. Do not edit.
|
|
||||||
# To update it, modify .github/workflow-generator.yml as needed and re-run the generator.
|
|
||||||
|
|
||||||
name: "Release Train – Test"
|
|
||||||
run-name: "${{ inputs.callback-ref }} – Test"
|
|
||||||
"on":
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
callback:
|
|
||||||
description: "Repository to which a callback should be made upon completion"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
callback-ref:
|
|
||||||
description: "Ref in the callback repository to which a callback should be made upon completion"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
release-train-maven-repository-url:
|
|
||||||
description: "URL of a Maven repository to be used to resolve artifacts of projects earlier in the train"
|
|
||||||
required: true
|
|
||||||
type: "string"
|
|
||||||
permissions:
|
|
||||||
contents: "read"
|
|
||||||
concurrency:
|
|
||||||
group: "${{ github.workflow }}-${{ github.ref }}"
|
|
||||||
jobs:
|
|
||||||
test-release:
|
|
||||||
name: "Test Release"
|
|
||||||
runs-on: "ubuntu22-2-8"
|
|
||||||
steps:
|
|
||||||
- name: "Prevent Re-runs"
|
|
||||||
id: "prevent-re-runs"
|
|
||||||
run: |-
|
|
||||||
if [ "$GITHUB_RUN_ATTEMPT" -gt 1 ]; then
|
|
||||||
echo "Re-runs are prohibited. Use the 'Release Train – Retry' workflow to retry test failures"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
- name: "Set up Java"
|
|
||||||
id: "set-up-java"
|
|
||||||
uses: "actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95" # v5.6.0
|
|
||||||
with:
|
|
||||||
distribution: "liberica"
|
|
||||||
java-version: "25"
|
|
||||||
- name: "Check Out Code"
|
|
||||||
id: "check-out-code"
|
|
||||||
uses: "actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0" # v7.0.0
|
|
||||||
- name: "Restore Build System Caches"
|
|
||||||
id: "restore-build-system-caches"
|
|
||||||
uses: "actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9" # v6.1.0
|
|
||||||
with:
|
|
||||||
key: "release-train-${{ inputs.callback-ref }}-${{ github.ref_name }}"
|
|
||||||
path: |-
|
|
||||||
~/.gradle/caches
|
|
||||||
~/.gradle/wrapper
|
|
||||||
- name: "Test Release"
|
|
||||||
id: "test-release"
|
|
||||||
uses: "./.github/actions/release-train-test"
|
|
||||||
env:
|
|
||||||
COMMERCIAL_REPO_PASSWORD: "${{ secrets.COMMERCIAL_ARTIFACTORY_PASSWORD }}"
|
|
||||||
COMMERCIAL_REPO_USERNAME: "${{ secrets.COMMERCIAL_ARTIFACTORY_USERNAME }}"
|
|
||||||
RELEASE_TRAIN_MAVEN_REPOSITORY_PASSWORD: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_MAVEN_REPOSITORY_PASSWORD }}"
|
|
||||||
RELEASE_TRAIN_MAVEN_REPOSITORY_URL: "${{ inputs.release-train-maven-repository-url }}"
|
|
||||||
RELEASE_TRAIN_MAVEN_REPOSITORY_USERNAME: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_MAVEN_REPOSITORY_USERNAME }}"
|
|
||||||
- name: "Send Callback"
|
|
||||||
id: "send-callback"
|
|
||||||
if: "${{ !cancelled() }}"
|
|
||||||
env:
|
|
||||||
GH_TOKEN: "${{ secrets.RELEASE_TRAIN_PARTICIPANT_GITHUB_TOKEN }}"
|
|
||||||
run: |-
|
|
||||||
gh workflow run callback \
|
|
||||||
--repo ${{ inputs.callback }} \
|
|
||||||
--ref ${{ inputs.callback-ref }} \
|
|
||||||
--field commit-hash=${{ steps.check-out-code.outputs.commit }} \
|
|
||||||
--field release-branch=${{ github.ref_name }} \
|
|
||||||
--field release-repository=${{ github.repository }} \
|
|
||||||
--field result=${{ job.status == 'success' && 'tested' || 'test-failed' }} \
|
|
||||||
--field workflow-run-url=${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
|
|
||||||
- name: "Upload Build System Reports"
|
|
||||||
id: "upload-build-system-reports"
|
|
||||||
if: "${{ failure() }}"
|
|
||||||
uses: "actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a" # v7.0.1
|
|
||||||
with:
|
|
||||||
name: "build-system-reports"
|
|
||||||
path: "**/build/reports"
|
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
name: Update Antora UI Spring
|
||||||
|
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: '0 10 * * *' # Once per day at 10am UTC
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
pull-requests: write
|
||||||
|
issues: write
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
update-antora-ui-spring:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Update on Supported Branches
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
branch: [ '5.8.x', '6.2.x', '6.3.x', 'main' ]
|
||||||
|
steps:
|
||||||
|
- uses: spring-io/spring-doc-actions/update-antora-spring-ui@e28269199d1d27975cf7f65e16d6095c555b3cd0
|
||||||
|
name: Update
|
||||||
|
with:
|
||||||
|
docs-branch: ${{ matrix.branch }}
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
antora-file-path: 'docs/antora-playbook.yml'
|
||||||
|
update-antora-ui-spring-docs-build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Update on docs-build
|
||||||
|
steps:
|
||||||
|
- uses: spring-io/spring-doc-actions/update-antora-spring-ui@e28269199d1d27975cf7f65e16d6095c555b3cd0
|
||||||
|
name: Update
|
||||||
|
with:
|
||||||
|
docs-branch: 'docs-build'
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
name: Update Scheduled Release Version
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch: # Manual trigger only. Triggered by release-scheduler.yml on main.
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
update-scheduled-release-version:
|
||||||
|
name: Update Scheduled Release Version
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/workflows/update-scheduled-release-version.yml@v1
|
||||||
|
secrets: inherit
|
||||||
|
send-notification:
|
||||||
|
name: Send Notification
|
||||||
|
needs: [ update-scheduled-release-version ]
|
||||||
|
if: ${{ failure() || cancelled() }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Send Notification
|
||||||
|
uses: spring-io/spring-security-release-tools/.github/actions/send-notification@v1
|
||||||
|
with:
|
||||||
|
webhook-url: ${{ secrets.SPRING_SECURITY_CI_GCHAT_WEBHOOK_URL }}
|
||||||
@@ -3,4 +3,4 @@
|
|||||||
# See https://sdkman.io/usage#config
|
# See https://sdkman.io/usage#config
|
||||||
# A summary is to add the following to ~/.sdkman/etc/config
|
# A summary is to add the following to ~/.sdkman/etc/config
|
||||||
# sdkman_auto_env=true
|
# sdkman_auto_env=true
|
||||||
java=25-librca
|
java=17.0.3-tem
|
||||||
|
|||||||
Vendored
+1
-1
@@ -1,3 +1,3 @@
|
|||||||
{
|
{
|
||||||
"java.gradle.buildServer.enabled": "off"
|
"java.import.gradle.enabled": false
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-2
@@ -31,7 +31,7 @@ If you have a question, check Stack Overflow using
|
|||||||
https://stackoverflow.com/questions/tagged/spring-security+or+spring-ldap+or+spring-authorization-server+or+spring-session?tab=Newest[this list of tags].
|
https://stackoverflow.com/questions/tagged/spring-security+or+spring-ldap+or+spring-authorization-server+or+spring-session?tab=Newest[this list of tags].
|
||||||
Find an existing discussion, or start a new one if necessary.
|
Find an existing discussion, or start a new one if necessary.
|
||||||
|
|
||||||
If you believe there is an issue, search through https://github.com/spring-projects/spring-security/issues[existing issues] trying a few different ways to find discussions, past or current, that are related to the issue.
|
If you believe there is an issue, search through https://github.com/spring-projects/spring-security/issues[existing issues] trying a few different ways to find discussions, past or current, that are related to the issue.
|
||||||
Reading those discussions helps you to learn about the issue, and helps us to make a decision.
|
Reading those discussions helps you to learn about the issue, and helps us to make a decision.
|
||||||
|
|
||||||
[[find-an-issue]]
|
[[find-an-issue]]
|
||||||
@@ -94,7 +94,7 @@ Don't worry if you don't get them all correct the first time, we will help you.
|
|||||||
|
|
||||||
1. [[sign-cla]] All commits must include a __Signed-off-by__ trailer at the end of each commit message to indicate that the contributor agrees to the Developer Certificate of Origin.
|
1. [[sign-cla]] All commits must include a __Signed-off-by__ trailer at the end of each commit message to indicate that the contributor agrees to the Developer Certificate of Origin.
|
||||||
For additional details, please refer to the blog post https://spring.io/blog/2025/01/06/hello-dco-goodbye-cla-simplifying-contributions-to-spring[Hello DCO, Goodbye CLA: Simplifying Contributions to Spring].
|
For additional details, please refer to the blog post https://spring.io/blog/2025/01/06/hello-dco-goodbye-cla-simplifying-contributions-to-spring[Hello DCO, Goodbye CLA: Simplifying Contributions to Spring].
|
||||||
2. [[create-an-issue-list]] Must you https://github.com/spring-projects/spring-security/issues/new/choose[create an issue] first? No, but it is recommended for features and larger bug fixes. It's easier to discuss with the team first to determine the right fix or enhancement.
|
2. [[create-an-issue-list]] Must you https://github.com/spring-projects/spring-security/issues/new/choose[create an issue] first? No, but it is recommended for features and larger bug fixes. It's easier discuss with the team first to determine the right fix or enhancement.
|
||||||
For typos and straightforward bug fixes, starting with a pull request is encouraged.
|
For typos and straightforward bug fixes, starting with a pull request is encouraged.
|
||||||
Please include a description for context and motivation.
|
Please include a description for context and motivation.
|
||||||
Note that the team may close your pull request if it's not a fit for the project.
|
Note that the team may close your pull request if it's not a fit for the project.
|
||||||
|
|||||||
-21
@@ -68,27 +68,6 @@ The https://github.com/spring-projects/spring-security/tree/docs-build[playbook
|
|||||||
|
|
||||||
Discover more commands with `./gradlew tasks`.
|
Discover more commands with `./gradlew tasks`.
|
||||||
|
|
||||||
=== IDE setup (IntelliJ)
|
|
||||||
|
|
||||||
No special steps are needed to open Spring Security in IntelliJ.
|
|
||||||
|
|
||||||
=== IDE setup (Eclipse and VS Code)
|
|
||||||
|
|
||||||
To work in Eclipse or VS Code, first generate Eclipse metadata so you can import the project into Eclipse or VS Code:
|
|
||||||
|
|
||||||
[indent=0]
|
|
||||||
----
|
|
||||||
./gradlew cleanEclipse eclipse
|
|
||||||
----
|
|
||||||
|
|
||||||
If you have not built the project yet, run `./gradlew publishToMavenLocal` first so dependencies are resolved.
|
|
||||||
|
|
||||||
*VS Code:* Open the repository root as a folder. The repository includes `.vscode/settings.json` which disables automatic Gradle import so that the generated Eclipse metadata (`.classpath`, `.project`) is used. Do not use the Gradle for Java extension to import the project.
|
|
||||||
|
|
||||||
*Eclipse:* File → Import → General → Existing Projects into Workspace, then select the repository root.
|
|
||||||
|
|
||||||
The build uses a custom Eclipse plugin to work around Gradle dependency cycles that confuse IDE metadata generation. You may see Eclipse warnings about `xml-apis` from some test dependencies; those are excluded in the build and can be ignored.
|
|
||||||
|
|
||||||
== Getting Support
|
== Getting Support
|
||||||
Check out the https://stackoverflow.com/questions/tagged/spring-security[Spring Security tags on Stack Overflow].
|
Check out the https://stackoverflow.com/questions/tagged/spring-security[Spring Security tags on Stack Overflow].
|
||||||
https://spring.io/support[Commercial support] is available too.
|
https://spring.io/support[Commercial support] is available too.
|
||||||
|
|||||||
@@ -1,8 +1,3 @@
|
|||||||
plugins {
|
|
||||||
id 'compile-warnings-error'
|
|
||||||
id 'javadoc-warnings-error'
|
|
||||||
}
|
|
||||||
|
|
||||||
apply plugin: 'io.spring.convention.spring-module'
|
apply plugin: 'io.spring.convention.spring-module'
|
||||||
|
|
||||||
dependencies {
|
dependencies {
|
||||||
|
|||||||
@@ -20,8 +20,6 @@ import java.io.Serial;
|
|||||||
import java.util.ArrayList;
|
import java.util.ArrayList;
|
||||||
import java.util.List;
|
import java.util.List;
|
||||||
|
|
||||||
import org.jspecify.annotations.Nullable;
|
|
||||||
|
|
||||||
import org.springframework.security.authorization.AuthorizationManager;
|
import org.springframework.security.authorization.AuthorizationManager;
|
||||||
import org.springframework.security.core.annotation.SecurityAnnotationScanner;
|
import org.springframework.security.core.annotation.SecurityAnnotationScanner;
|
||||||
import org.springframework.util.Assert;
|
import org.springframework.util.Assert;
|
||||||
@@ -52,7 +50,7 @@ public class SecurityConfig implements ConfigAttribute {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean equals(@Nullable Object obj) {
|
public boolean equals(Object obj) {
|
||||||
if (obj instanceof ConfigAttribute attr) {
|
if (obj instanceof ConfigAttribute attr) {
|
||||||
return this.attrib.equals(attr.getAttribute());
|
return this.attrib.equals(attr.getAttribute());
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-2
@@ -31,7 +31,6 @@ import org.jspecify.annotations.Nullable;
|
|||||||
import org.springframework.core.annotation.AnnotationUtils;
|
import org.springframework.core.annotation.AnnotationUtils;
|
||||||
import org.springframework.security.access.ConfigAttribute;
|
import org.springframework.security.access.ConfigAttribute;
|
||||||
import org.springframework.security.access.method.AbstractFallbackMethodSecurityMetadataSource;
|
import org.springframework.security.access.method.AbstractFallbackMethodSecurityMetadataSource;
|
||||||
import org.springframework.util.StringUtils;
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Sources method security metadata from major JSR 250 security annotations.
|
* Sources method security metadata from major JSR 250 security annotations.
|
||||||
@@ -109,7 +108,7 @@ public class Jsr250MethodSecurityMetadataSource extends AbstractFallbackMethodSe
|
|||||||
if (role == null) {
|
if (role == null) {
|
||||||
return role;
|
return role;
|
||||||
}
|
}
|
||||||
if (!StringUtils.hasLength(this.defaultRolePrefix)) {
|
if (this.defaultRolePrefix == null || this.defaultRolePrefix.length() == 0) {
|
||||||
return role;
|
return role;
|
||||||
}
|
}
|
||||||
if (role.startsWith(this.defaultRolePrefix)) {
|
if (role.startsWith(this.defaultRolePrefix)) {
|
||||||
|
|||||||
+1
-3
@@ -53,9 +53,7 @@ import org.springframework.util.CollectionUtils;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @deprecated Use
|
* @deprecated Use {@link EnableMethodSecurity} or publish interceptors directly
|
||||||
* <code>org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity</code>
|
|
||||||
* or publish interceptors directly
|
|
||||||
*/
|
*/
|
||||||
@NullUnmarked
|
@NullUnmarked
|
||||||
@Deprecated
|
@Deprecated
|
||||||
|
|||||||
+2
-4
@@ -114,10 +114,8 @@ public final class DelegatingMethodSecurityMetadataSource extends AbstractMethod
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean equals(@Nullable Object other) {
|
public boolean equals(Object other) {
|
||||||
if (!(other instanceof DefaultCacheKey otherKey)) {
|
DefaultCacheKey otherKey = (DefaultCacheKey) other;
|
||||||
return false;
|
|
||||||
}
|
|
||||||
return (this.method.equals(otherKey.method)
|
return (this.method.equals(otherKey.method)
|
||||||
&& ObjectUtils.nullSafeEquals(this.targetClass, otherKey.targetClass));
|
&& ObjectUtils.nullSafeEquals(this.targetClass, otherKey.targetClass));
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-1
@@ -265,7 +265,7 @@ public class MapBasedMethodSecurityMetadataSource extends AbstractFallbackMethod
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean equals(@Nullable Object obj) {
|
public boolean equals(Object obj) {
|
||||||
if (this == obj) {
|
if (this == obj) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|||||||
-1
@@ -145,7 +145,6 @@ public class PrePostAdviceReactiveMethodInterceptor implements MethodInterceptor
|
|||||||
.map((r) -> (attr != null) ? this.postAdvice.after(auth, invocation, attr, r) : r));
|
.map((r) -> (attr != null) ? this.postAdvice.after(auth, invocation, attr, r) : r));
|
||||||
}
|
}
|
||||||
|
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
private static <T extends Publisher<?>> @Nullable T proceed(final MethodInvocation invocation) {
|
private static <T extends Publisher<?>> @Nullable T proceed(final MethodInvocation invocation) {
|
||||||
try {
|
try {
|
||||||
return (T) invocation.proceed();
|
return (T) invocation.proceed();
|
||||||
|
|||||||
-1
@@ -111,7 +111,6 @@ public class AclEntryAfterInvocationCollectionFilteringProvider extends Abstract
|
|||||||
return returnedObject;
|
return returnedObject;
|
||||||
}
|
}
|
||||||
|
|
||||||
@SuppressWarnings({ "unchecked", "rawtypes" })
|
|
||||||
private Filterer getFilterer(Object returnedObject) {
|
private Filterer getFilterer(Object returnedObject) {
|
||||||
if (returnedObject instanceof Collection) {
|
if (returnedObject instanceof Collection) {
|
||||||
return new CollectionFilterer((Collection) returnedObject);
|
return new CollectionFilterer((Collection) returnedObject);
|
||||||
|
|||||||
+1
-1
@@ -39,7 +39,7 @@ interface EvaluationContextPostProcessor<I> {
|
|||||||
* that was passed in.
|
* that was passed in.
|
||||||
* @param context the original {@link EvaluationContext}
|
* @param context the original {@link EvaluationContext}
|
||||||
* @param invocation the security invocation object (i.e. Message)
|
* @param invocation the security invocation object (i.e. Message)
|
||||||
* @return the updated context.
|
* @return the upated context.
|
||||||
*/
|
*/
|
||||||
EvaluationContext postProcess(EvaluationContext context, I invocation);
|
EvaluationContext postProcess(EvaluationContext context, I invocation);
|
||||||
|
|
||||||
|
|||||||
-1
@@ -50,7 +50,6 @@ class MessageExpressionConfigAttribute implements ConfigAttribute, EvaluationCon
|
|||||||
* @param authorizeExpression the {@link Expression} to use. Cannot be null
|
* @param authorizeExpression the {@link Expression} to use. Cannot be null
|
||||||
* @param matcher the {@link MessageMatcher} used to match the messages.
|
* @param matcher the {@link MessageMatcher} used to match the messages.
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
MessageExpressionConfigAttribute(Expression authorizeExpression, MessageMatcher<?> matcher) {
|
MessageExpressionConfigAttribute(Expression authorizeExpression, MessageMatcher<?> matcher) {
|
||||||
Assert.notNull(authorizeExpression, "authorizeExpression cannot be null");
|
Assert.notNull(authorizeExpression, "authorizeExpression cannot be null");
|
||||||
Assert.notNull(matcher, "matcher cannot be null");
|
Assert.notNull(matcher, "matcher cannot be null");
|
||||||
|
|||||||
-1
@@ -41,7 +41,6 @@ public class DefaultWebSecurityExpressionHandler extends AbstractSecurityExpress
|
|||||||
private String defaultRolePrefix = DEFAULT_ROLE_PREFIX;
|
private String defaultRolePrefix = DEFAULT_ROLE_PREFIX;
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
protected SecurityExpressionOperations createSecurityExpressionRoot(@Nullable Authentication authentication,
|
protected SecurityExpressionOperations createSecurityExpressionRoot(@Nullable Authentication authentication,
|
||||||
FilterInvocation fi) {
|
FilterInvocation fi) {
|
||||||
FilterInvocationExpressionRoot root = new FilterInvocationExpressionRoot(() -> authentication, fi);
|
FilterInvocationExpressionRoot root = new FilterInvocationExpressionRoot(() -> authentication, fi);
|
||||||
|
|||||||
-1
@@ -35,7 +35,6 @@ import org.springframework.security.web.FilterInvocation;
|
|||||||
*/
|
*/
|
||||||
@Deprecated
|
@Deprecated
|
||||||
@NullUnmarked
|
@NullUnmarked
|
||||||
@SuppressWarnings("serial")
|
|
||||||
class WebExpressionConfigAttribute implements ConfigAttribute, EvaluationContextPostProcessor<FilterInvocation> {
|
class WebExpressionConfigAttribute implements ConfigAttribute, EvaluationContextPostProcessor<FilterInvocation> {
|
||||||
|
|
||||||
private final Expression authorizeExpression;
|
private final Expression authorizeExpression;
|
||||||
|
|||||||
-1
@@ -29,7 +29,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AuthenticationCredentialsNotFoundEventTests {
|
public class AuthenticationCredentialsNotFoundEventTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -32,7 +32,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AuthorizationFailureEventTests {
|
public class AuthorizationFailureEventTests {
|
||||||
|
|
||||||
private final UsernamePasswordAuthenticationToken foo = UsernamePasswordAuthenticationToken.unauthenticated("foo",
|
private final UsernamePasswordAuthenticationToken foo = UsernamePasswordAuthenticationToken.unauthenticated("foo",
|
||||||
|
|||||||
@@ -29,7 +29,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AuthorizedEventTests {
|
public class AuthorizedEventTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
@@ -27,7 +27,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class SecurityConfigTests {
|
public class SecurityConfigTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -32,7 +32,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class Jsr250MethodSecurityMetadataSourceTests {
|
public class Jsr250MethodSecurityMetadataSourceTests {
|
||||||
|
|
||||||
Jsr250MethodSecurityMetadataSource mds;
|
Jsr250MethodSecurityMetadataSource mds;
|
||||||
|
|||||||
-1
@@ -31,7 +31,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class Jsr250VoterTests {
|
public class Jsr250VoterTests {
|
||||||
|
|
||||||
// SEC-1443
|
// SEC-1443
|
||||||
|
|||||||
-1
@@ -46,7 +46,6 @@ import static org.assertj.core.api.Assertions.fail;
|
|||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class SecuredAnnotationSecurityMetadataSourceTests {
|
public class SecuredAnnotationSecurityMetadataSourceTests {
|
||||||
|
|
||||||
private SecuredAnnotationSecurityMetadataSource mds = new SecuredAnnotationSecurityMetadataSource();
|
private SecuredAnnotationSecurityMetadataSource mds = new SecuredAnnotationSecurityMetadataSource();
|
||||||
|
|||||||
+1
-3
@@ -79,13 +79,11 @@ public class DefaultMethodSecurityExpressionHandlerTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public void setTrustResolverNull() {
|
public void setTrustResolverNull() {
|
||||||
assertThatIllegalArgumentException().isThrownBy(() -> this.handler.setTrustResolver(null));
|
assertThatIllegalArgumentException().isThrownBy(() -> this.handler.setTrustResolver(null));
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public void createEvaluationContextCustomTrustResolver() {
|
public void createEvaluationContextCustomTrustResolver() {
|
||||||
setupMocks();
|
setupMocks();
|
||||||
this.handler.setTrustResolver(this.trustResolver);
|
this.handler.setTrustResolver(this.trustResolver);
|
||||||
@@ -177,7 +175,7 @@ public class DefaultMethodSecurityExpressionHandlerTests {
|
|||||||
@Test
|
@Test
|
||||||
public void createEvaluationContextSupplierAuthentication() {
|
public void createEvaluationContextSupplierAuthentication() {
|
||||||
setupMocks();
|
setupMocks();
|
||||||
Supplier<Authentication> mockAuthenticationSupplier = mock();
|
Supplier<Authentication> mockAuthenticationSupplier = mock(Supplier.class);
|
||||||
given(mockAuthenticationSupplier.get()).willReturn(this.authentication);
|
given(mockAuthenticationSupplier.get()).willReturn(this.authentication);
|
||||||
EvaluationContext context = this.handler.createEvaluationContext(mockAuthenticationSupplier,
|
EvaluationContext context = this.handler.createEvaluationContext(mockAuthenticationSupplier,
|
||||||
this.methodInvocation);
|
this.methodInvocation);
|
||||||
|
|||||||
-1
@@ -39,7 +39,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
* @since 5.2
|
* @since 5.2
|
||||||
*/
|
*/
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class ExpressionBasedPreInvocationAdviceTests {
|
public class ExpressionBasedPreInvocationAdviceTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
|
|||||||
+1
-1
@@ -34,7 +34,7 @@ import org.springframework.security.util.SimpleMethodInvocation;
|
|||||||
import static org.assertj.core.api.Assertions.assertThat;
|
import static org.assertj.core.api.Assertions.assertThat;
|
||||||
import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException;
|
import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException;
|
||||||
|
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings("unchecked")
|
||||||
public class MethodExpressionVoterTests {
|
public class MethodExpressionVoterTests {
|
||||||
|
|
||||||
private TestingAuthenticationToken joe = new TestingAuthenticationToken("joe", "joespass", "ROLE_blah");
|
private TestingAuthenticationToken joe = new TestingAuthenticationToken("joe", "joespass", "ROLE_blah");
|
||||||
|
|||||||
+1
-4
@@ -27,7 +27,6 @@ import org.springframework.expression.spel.support.StandardEvaluationContext;
|
|||||||
import org.springframework.security.access.PermissionEvaluator;
|
import org.springframework.security.access.PermissionEvaluator;
|
||||||
import org.springframework.security.access.expression.ExpressionUtils;
|
import org.springframework.security.access.expression.ExpressionUtils;
|
||||||
import org.springframework.security.authentication.AuthenticationTrustResolver;
|
import org.springframework.security.authentication.AuthenticationTrustResolver;
|
||||||
import org.springframework.security.authorization.DefaultAuthorizationManagerFactory;
|
|
||||||
import org.springframework.security.core.Authentication;
|
import org.springframework.security.core.Authentication;
|
||||||
|
|
||||||
import static org.mockito.ArgumentMatchers.any;
|
import static org.mockito.ArgumentMatchers.any;
|
||||||
@@ -59,9 +58,7 @@ public class MethodSecurityExpressionRootTests {
|
|||||||
this.ctx = new StandardEvaluationContext();
|
this.ctx = new StandardEvaluationContext();
|
||||||
this.ctx.setRootObject(this.root);
|
this.ctx.setRootObject(this.root);
|
||||||
this.trustResolver = mock(AuthenticationTrustResolver.class);
|
this.trustResolver = mock(AuthenticationTrustResolver.class);
|
||||||
DefaultAuthorizationManagerFactory<MethodInvocation> authorizationManagerFactory = new DefaultAuthorizationManagerFactory<>();
|
this.root.setTrustResolver(this.trustResolver);
|
||||||
authorizationManagerFactory.setTrustResolver(this.trustResolver);
|
|
||||||
this.root.setAuthorizationManagerFactory(authorizationManagerFactory);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -44,7 +44,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @since 3.0
|
* @since 3.0
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class PrePostAnnotationSecurityMetadataSourceTests {
|
public class PrePostAnnotationSecurityMetadataSourceTests {
|
||||||
|
|
||||||
private PrePostAnnotationSecurityMetadataSource mds = new PrePostAnnotationSecurityMetadataSource(
|
private PrePostAnnotationSecurityMetadataSource mds = new PrePostAnnotationSecurityMetadataSource(
|
||||||
|
|||||||
-1
@@ -32,7 +32,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AbstractSecurityInterceptorTests {
|
public class AbstractSecurityInterceptorTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
+1
-1
@@ -38,7 +38,7 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings("unchecked")
|
||||||
public class AfterInvocationProviderManagerTests {
|
public class AfterInvocationProviderManagerTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -34,7 +34,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class InterceptorStatusTokenTests {
|
public class InterceptorStatusTokenTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -27,7 +27,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class NullRunAsManagerTests {
|
public class NullRunAsManagerTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -31,7 +31,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
/**
|
/**
|
||||||
* Tests {@link RunAsImplAuthenticationProvider}.
|
* Tests {@link RunAsImplAuthenticationProvider}.
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RunAsImplAuthenticationProviderTests {
|
public class RunAsImplAuthenticationProviderTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -34,7 +34,6 @@ import static org.assertj.core.api.Assertions.fail;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RunAsManagerImplTests {
|
public class RunAsManagerImplTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -29,7 +29,6 @@ import static org.assertj.core.api.Assertions.assertThatExceptionOfType;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RunAsUserTokenTests {
|
public class RunAsUserTokenTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
+1
-1
@@ -65,7 +65,7 @@ import static org.mockito.Mockito.verifyNoMoreInteractions;
|
|||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
* @author Rob Winch
|
* @author Rob Winch
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings("unchecked")
|
||||||
public class MethodSecurityInterceptorTests {
|
public class MethodSecurityInterceptorTests {
|
||||||
|
|
||||||
private TestingAuthenticationToken token;
|
private TestingAuthenticationToken token;
|
||||||
|
|||||||
-1
@@ -33,7 +33,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class MethodSecurityMetadataSourceAdvisorTests {
|
public class MethodSecurityMetadataSourceAdvisorTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -62,7 +62,6 @@ import static org.mockito.Mockito.verifyNoMoreInteractions;
|
|||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @author Rob Winch
|
* @author Rob Winch
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AspectJMethodSecurityInterceptorTests {
|
public class AspectJMethodSecurityInterceptorTests {
|
||||||
|
|
||||||
private TestingAuthenticationToken token;
|
private TestingAuthenticationToken token;
|
||||||
|
|||||||
-1
@@ -34,7 +34,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @since 2.0.4
|
* @since 2.0.4
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class MapBasedMethodSecurityMetadataSourceTests {
|
public class MapBasedMethodSecurityMetadataSourceTests {
|
||||||
|
|
||||||
private final List<ConfigAttribute> ROLE_A = SecurityConfig.createList("ROLE_A");
|
private final List<ConfigAttribute> ROLE_A = SecurityConfig.createList("ROLE_A");
|
||||||
|
|||||||
-1
@@ -49,7 +49,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class MethodInvocationPrivilegeEvaluatorTests {
|
public class MethodInvocationPrivilegeEvaluatorTests {
|
||||||
|
|
||||||
private TestingAuthenticationToken token;
|
private TestingAuthenticationToken token;
|
||||||
|
|||||||
+1
-1
@@ -36,7 +36,7 @@ import static org.mockito.Mockito.mock;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings({ "unchecked" })
|
||||||
public class DelegatingMethodSecurityMetadataSourceTests {
|
public class DelegatingMethodSecurityMetadataSourceTests {
|
||||||
|
|
||||||
DelegatingMethodSecurityMetadataSource mds;
|
DelegatingMethodSecurityMetadataSource mds;
|
||||||
|
|||||||
-1
@@ -29,7 +29,6 @@ import org.springframework.security.access.intercept.aspectj.MethodInvocationAda
|
|||||||
import static org.assertj.core.api.Assertions.assertThat;
|
import static org.assertj.core.api.Assertions.assertThat;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class PostInvocationAdviceProviderTests {
|
public class PostInvocationAdviceProviderTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
|
|||||||
-1
@@ -29,7 +29,6 @@ import org.springframework.security.access.intercept.aspectj.MethodInvocationAda
|
|||||||
import static org.assertj.core.api.Assertions.assertThat;
|
import static org.assertj.core.api.Assertions.assertThat;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class PreInvocationAuthorizationAdviceVoterTests {
|
public class PreInvocationAuthorizationAdviceVoterTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
|
|||||||
+1
-1
@@ -36,7 +36,7 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings("unchecked")
|
||||||
public class AbstractAccessDecisionManagerTests {
|
public class AbstractAccessDecisionManagerTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -31,7 +31,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AbstractAclVoterTests {
|
public class AbstractAclVoterTests {
|
||||||
|
|
||||||
private AbstractAclVoter voter = new AbstractAclVoter() {
|
private AbstractAclVoter voter = new AbstractAclVoter() {
|
||||||
|
|||||||
-1
@@ -40,7 +40,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AffirmativeBasedTests {
|
public class AffirmativeBasedTests {
|
||||||
|
|
||||||
private final List<ConfigAttribute> attrs = new ArrayList<>();
|
private final List<ConfigAttribute> attrs = new ArrayList<>();
|
||||||
|
|||||||
-1
@@ -37,7 +37,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class AuthenticatedVoterTests {
|
public class AuthenticatedVoterTests {
|
||||||
|
|
||||||
private Authentication createAnonymous() {
|
private Authentication createAnonymous() {
|
||||||
|
|||||||
@@ -35,7 +35,6 @@ import static org.assertj.core.api.Assertions.assertThatExceptionOfType;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class ConsensusBasedTests {
|
public class ConsensusBasedTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
@@ -32,7 +32,6 @@ import org.springframework.security.core.Authentication;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class DenyAgainVoter implements AccessDecisionVoter<Object> {
|
public class DenyAgainVoter implements AccessDecisionVoter<Object> {
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
@@ -34,7 +34,6 @@ import org.springframework.security.core.Authentication;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class DenyVoter implements AccessDecisionVoter<Object> {
|
public class DenyVoter implements AccessDecisionVoter<Object> {
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
-1
@@ -25,7 +25,6 @@ import org.springframework.security.authentication.TestingAuthenticationToken;
|
|||||||
|
|
||||||
import static org.assertj.core.api.Assertions.assertThat;
|
import static org.assertj.core.api.Assertions.assertThat;
|
||||||
|
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RoleHierarchyVoterTests {
|
public class RoleHierarchyVoterTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
@@ -28,7 +28,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RoleVoterTests {
|
public class RoleVoterTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
@@ -35,7 +35,6 @@ import static org.assertj.core.api.Assertions.assertThatExceptionOfType;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class UnanimousBasedTests {
|
public class UnanimousBasedTests {
|
||||||
|
|
||||||
private UnanimousBased makeDecisionManager() {
|
private UnanimousBased makeDecisionManager() {
|
||||||
|
|||||||
+1
-1
@@ -44,7 +44,7 @@ import static org.mockito.Mockito.verify;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings({ "unchecked" })
|
||||||
public class AclEntryAfterInvocationCollectionFilteringProviderTests {
|
public class AclEntryAfterInvocationCollectionFilteringProviderTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
+1
-1
@@ -48,7 +48,7 @@ import static org.mockito.Mockito.verify;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings({ "unchecked" })
|
||||||
public class AclEntryAfterInvocationProviderTests {
|
public class AclEntryAfterInvocationProviderTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
+2
-3
@@ -35,7 +35,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
import static org.mockito.BDDMockito.given;
|
import static org.mockito.BDDMockito.given;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class ExpressionBasedMessageSecurityMetadataSourceFactoryTests {
|
public class ExpressionBasedMessageSecurityMetadataSourceFactoryTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
@@ -58,7 +57,7 @@ public class ExpressionBasedMessageSecurityMetadataSourceFactoryTests {
|
|||||||
|
|
||||||
MessageSecurityMetadataSource source;
|
MessageSecurityMetadataSource source;
|
||||||
|
|
||||||
MessageSecurityExpressionRoot<Object> rootObject;
|
MessageSecurityExpressionRoot rootObject;
|
||||||
|
|
||||||
@BeforeEach
|
@BeforeEach
|
||||||
public void setup() {
|
public void setup() {
|
||||||
@@ -69,7 +68,7 @@ public class ExpressionBasedMessageSecurityMetadataSourceFactoryTests {
|
|||||||
this.matcherToExpression.put(this.matcher2, this.expression2);
|
this.matcherToExpression.put(this.matcher2, this.expression2);
|
||||||
this.source = ExpressionBasedMessageSecurityMetadataSourceFactory
|
this.source = ExpressionBasedMessageSecurityMetadataSourceFactory
|
||||||
.createExpressionMessageMetadataSource(this.matcherToExpression);
|
.createExpressionMessageMetadataSource(this.matcherToExpression);
|
||||||
this.rootObject = new MessageSecurityExpressionRoot<>(this.authentication, this.message);
|
this.rootObject = new MessageSecurityExpressionRoot(this.authentication, this.message);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -37,7 +37,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
import static org.mockito.Mockito.verify;
|
import static org.mockito.Mockito.verify;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class MessageExpressionConfigAttributeTests {
|
public class MessageExpressionConfigAttributeTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
|
|||||||
-9
@@ -44,7 +44,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
import static org.mockito.Mockito.verify;
|
import static org.mockito.Mockito.verify;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class MessageExpressionVoterTests {
|
public class MessageExpressionVoterTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
@@ -77,7 +76,6 @@ public class MessageExpressionVoterTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void voteGranted() {
|
public void voteGranted() {
|
||||||
given(this.expression.getValue(any(EvaluationContext.class), eq(Boolean.class))).willReturn(true);
|
given(this.expression.getValue(any(EvaluationContext.class), eq(Boolean.class))).willReturn(true);
|
||||||
given(this.matcher.matcher(any())).willCallRealMethod();
|
given(this.matcher.matcher(any())).willCallRealMethod();
|
||||||
@@ -86,7 +84,6 @@ public class MessageExpressionVoterTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void voteDenied() {
|
public void voteDenied() {
|
||||||
given(this.expression.getValue(any(EvaluationContext.class), eq(Boolean.class))).willReturn(false);
|
given(this.expression.getValue(any(EvaluationContext.class), eq(Boolean.class))).willReturn(false);
|
||||||
given(this.matcher.matcher(any())).willCallRealMethod();
|
given(this.matcher.matcher(any())).willCallRealMethod();
|
||||||
@@ -95,7 +92,6 @@ public class MessageExpressionVoterTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void voteAbstain() {
|
public void voteAbstain() {
|
||||||
this.attributes = Arrays.<ConfigAttribute>asList(new SecurityConfig("ROLE_USER"));
|
this.attributes = Arrays.<ConfigAttribute>asList(new SecurityConfig("ROLE_USER"));
|
||||||
assertThat(this.voter.vote(this.authentication, this.message, this.attributes))
|
assertThat(this.voter.vote(this.authentication, this.message, this.attributes))
|
||||||
@@ -103,13 +99,11 @@ public class MessageExpressionVoterTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void supportsObjectClassFalse() {
|
public void supportsObjectClassFalse() {
|
||||||
assertThat(this.voter.supports(Object.class)).isFalse();
|
assertThat(this.voter.supports(Object.class)).isFalse();
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void supportsMessageClassTrue() {
|
public void supportsMessageClassTrue() {
|
||||||
assertThat(this.voter.supports(Message.class)).isTrue();
|
assertThat(this.voter.supports(Message.class)).isTrue();
|
||||||
}
|
}
|
||||||
@@ -125,13 +119,11 @@ public class MessageExpressionVoterTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void setExpressionHandlerNull() {
|
public void setExpressionHandlerNull() {
|
||||||
assertThatIllegalArgumentException().isThrownBy(() -> this.voter.setExpressionHandler(null));
|
assertThatIllegalArgumentException().isThrownBy(() -> this.voter.setExpressionHandler(null));
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void customExpressionHandler() {
|
public void customExpressionHandler() {
|
||||||
this.voter.setExpressionHandler(this.expressionHandler);
|
this.voter.setExpressionHandler(this.expressionHandler);
|
||||||
given(this.expressionHandler.createEvaluationContext(this.authentication, this.message))
|
given(this.expressionHandler.createEvaluationContext(this.authentication, this.message))
|
||||||
@@ -144,7 +136,6 @@ public class MessageExpressionVoterTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("unchecked")
|
|
||||||
public void postProcessEvaluationContext() {
|
public void postProcessEvaluationContext() {
|
||||||
final MessageExpressionConfigAttribute configAttribute = mock(MessageExpressionConfigAttribute.class);
|
final MessageExpressionConfigAttribute configAttribute = mock(MessageExpressionConfigAttribute.class);
|
||||||
this.voter.setExpressionHandler(this.expressionHandler);
|
this.voter.setExpressionHandler(this.expressionHandler);
|
||||||
|
|||||||
-1
@@ -47,7 +47,6 @@ import static org.mockito.BDDMockito.given;
|
|||||||
import static org.mockito.BDDMockito.willThrow;
|
import static org.mockito.BDDMockito.willThrow;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class ChannelSecurityInterceptorTests {
|
public class ChannelSecurityInterceptorTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
|
|||||||
-1
@@ -36,7 +36,6 @@ import static org.assertj.core.api.Assertions.assertThat;
|
|||||||
import static org.mockito.BDDMockito.given;
|
import static org.mockito.BDDMockito.given;
|
||||||
|
|
||||||
@ExtendWith(MockitoExtension.class)
|
@ExtendWith(MockitoExtension.class)
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class DefaultMessageSecurityMetadataSourceTests {
|
public class DefaultMessageSecurityMetadataSourceTests {
|
||||||
|
|
||||||
@Mock
|
@Mock
|
||||||
|
|||||||
-1
@@ -43,7 +43,6 @@ import org.springframework.security.web.access.intercept.FilterSecurityIntercept
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class DefaultWebInvocationPrivilegeEvaluatorTests {
|
public class DefaultWebInvocationPrivilegeEvaluatorTests {
|
||||||
|
|
||||||
private AccessDecisionManager adm;
|
private AccessDecisionManager adm;
|
||||||
|
|||||||
+1
-1
@@ -42,7 +42,7 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings("unchecked")
|
||||||
public class ChannelDecisionManagerImplTests {
|
public class ChannelDecisionManagerImplTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -39,7 +39,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class ChannelProcessingFilterTests {
|
public class ChannelProcessingFilterTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -35,7 +35,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class InsecureChannelProcessorTests {
|
public class InsecureChannelProcessorTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -36,7 +36,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RetryWithHttpEntryPointTests {
|
public class RetryWithHttpEntryPointTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -33,7 +33,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class RetryWithHttpsEntryPointTests {
|
public class RetryWithHttpsEntryPointTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-1
@@ -35,7 +35,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class SecureChannelProcessorTests {
|
public class SecureChannelProcessorTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
-3
@@ -64,7 +64,6 @@ public class DefaultWebSecurityExpressionHandlerTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public void expressionPropertiesAreResolvedAgainstAppContextBeans() {
|
public void expressionPropertiesAreResolvedAgainstAppContextBeans() {
|
||||||
StaticApplicationContext appContext = new StaticApplicationContext();
|
StaticApplicationContext appContext = new StaticApplicationContext();
|
||||||
RootBeanDefinition bean = new RootBeanDefinition(SecurityConfig.class);
|
RootBeanDefinition bean = new RootBeanDefinition(SecurityConfig.class);
|
||||||
@@ -79,13 +78,11 @@ public class DefaultWebSecurityExpressionHandlerTests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public void setTrustResolverNull() {
|
public void setTrustResolverNull() {
|
||||||
assertThatIllegalArgumentException().isThrownBy(() -> this.handler.setTrustResolver(null));
|
assertThatIllegalArgumentException().isThrownBy(() -> this.handler.setTrustResolver(null));
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public void createEvaluationContextCustomTrustResolver() {
|
public void createEvaluationContextCustomTrustResolver() {
|
||||||
this.handler.setTrustResolver(this.trustResolver);
|
this.handler.setTrustResolver(this.trustResolver);
|
||||||
Expression expression = this.handler.getExpressionParser().parseExpression("anonymous");
|
Expression expression = this.handler.getExpressionParser().parseExpression("anonymous");
|
||||||
|
|||||||
-1
@@ -33,7 +33,6 @@ import static org.assertj.core.api.Assertions.assertThatIllegalArgumentException
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class ExpressionBasedFilterInvocationSecurityMetadataSourceTests {
|
public class ExpressionBasedFilterInvocationSecurityMetadataSourceTests {
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
+1
-1
@@ -41,7 +41,7 @@ import static org.mockito.Mockito.mock;
|
|||||||
/**
|
/**
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings({ "unchecked", "deprecation" })
|
@SuppressWarnings({ "unchecked" })
|
||||||
public class WebExpressionVoterTests {
|
public class WebExpressionVoterTests {
|
||||||
|
|
||||||
private Authentication user = new TestingAuthenticationToken("user", "pass", "X");
|
private Authentication user = new TestingAuthenticationToken("user", "pass", "X");
|
||||||
|
|||||||
-1
@@ -40,7 +40,6 @@ import static org.mockito.Mockito.mock;
|
|||||||
*
|
*
|
||||||
* @author Ben Alex
|
* @author Ben Alex
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class DefaultFilterInvocationSecurityMetadataSourceTests {
|
public class DefaultFilterInvocationSecurityMetadataSourceTests {
|
||||||
|
|
||||||
private DefaultFilterInvocationSecurityMetadataSource fids;
|
private DefaultFilterInvocationSecurityMetadataSource fids;
|
||||||
|
|||||||
-1
@@ -62,7 +62,6 @@ import static org.mockito.Mockito.verifyNoMoreInteractions;
|
|||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @author Rob Winch
|
* @author Rob Winch
|
||||||
*/
|
*/
|
||||||
@SuppressWarnings("deprecation")
|
|
||||||
public class FilterSecurityInterceptorTests {
|
public class FilterSecurityInterceptorTests {
|
||||||
|
|
||||||
private AuthenticationManager am;
|
private AuthenticationManager am;
|
||||||
|
|||||||
@@ -1,9 +1,3 @@
|
|||||||
plugins {
|
|
||||||
id 'compile-warnings-error'
|
|
||||||
id 'javadoc-warnings-error'
|
|
||||||
id 'security-nullability'
|
|
||||||
}
|
|
||||||
|
|
||||||
apply plugin: 'io.spring.convention.spring-module'
|
apply plugin: 'io.spring.convention.spring-module'
|
||||||
|
|
||||||
dependencies {
|
dependencies {
|
||||||
|
|||||||
@@ -23,7 +23,6 @@ import java.util.Locale;
|
|||||||
|
|
||||||
import org.apache.commons.logging.Log;
|
import org.apache.commons.logging.Log;
|
||||||
import org.apache.commons.logging.LogFactory;
|
import org.apache.commons.logging.LogFactory;
|
||||||
import org.jspecify.annotations.Nullable;
|
|
||||||
|
|
||||||
import org.springframework.core.log.LogMessage;
|
import org.springframework.core.log.LogMessage;
|
||||||
import org.springframework.security.access.PermissionEvaluator;
|
import org.springframework.security.access.PermissionEvaluator;
|
||||||
@@ -45,7 +44,7 @@ import org.springframework.security.core.Authentication;
|
|||||||
/**
|
/**
|
||||||
* Used by Spring Security's expression-based access control implementation to evaluate
|
* Used by Spring Security's expression-based access control implementation to evaluate
|
||||||
* permissions for a particular object using the ACL module. Similar in behaviour to
|
* permissions for a particular object using the ACL module. Similar in behaviour to
|
||||||
* <code> org.springframework.security.acls.AclEntryVoter AclEntryVoter </code>
|
* {@link org.springframework.security.acls.AclEntryVoter AclEntryVoter}.
|
||||||
*
|
*
|
||||||
* @author Luke Taylor
|
* @author Luke Taylor
|
||||||
* @since 3.0
|
* @since 3.0
|
||||||
@@ -74,7 +73,7 @@ public class AclPermissionEvaluator implements PermissionEvaluator {
|
|||||||
* be overridden using a null check in the expression itself).
|
* be overridden using a null check in the expression itself).
|
||||||
*/
|
*/
|
||||||
@Override
|
@Override
|
||||||
public boolean hasPermission(Authentication authentication, @Nullable Object domainObject, Object permission) {
|
public boolean hasPermission(Authentication authentication, Object domainObject, Object permission) {
|
||||||
if (domainObject == null) {
|
if (domainObject == null) {
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,79 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright 2004-present the original author or authors.
|
|
||||||
*
|
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
* you may not use this file except in compliance with the License.
|
|
||||||
* You may obtain a copy of the License at
|
|
||||||
*
|
|
||||||
* https://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
*
|
|
||||||
* Unless required by applicable law or agreed to in writing, software
|
|
||||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
* See the License for the specific language governing permissions and
|
|
||||||
* limitations under the License.
|
|
||||||
*/
|
|
||||||
|
|
||||||
package org.springframework.security.acls.aot.hint;
|
|
||||||
|
|
||||||
import java.util.stream.Stream;
|
|
||||||
|
|
||||||
import org.jspecify.annotations.Nullable;
|
|
||||||
|
|
||||||
import org.springframework.aot.hint.MemberCategory;
|
|
||||||
import org.springframework.aot.hint.RuntimeHints;
|
|
||||||
import org.springframework.aot.hint.RuntimeHintsRegistrar;
|
|
||||||
import org.springframework.aot.hint.TypeReference;
|
|
||||||
import org.springframework.core.io.ClassPathResource;
|
|
||||||
import org.springframework.core.io.Resource;
|
|
||||||
import org.springframework.security.acls.domain.AclImpl;
|
|
||||||
import org.springframework.security.acls.domain.AuditLogger;
|
|
||||||
import org.springframework.security.acls.domain.BasePermission;
|
|
||||||
import org.springframework.security.acls.domain.GrantedAuthoritySid;
|
|
||||||
import org.springframework.security.acls.domain.ObjectIdentityImpl;
|
|
||||||
import org.springframework.security.acls.domain.PrincipalSid;
|
|
||||||
import org.springframework.security.acls.model.AccessControlEntry;
|
|
||||||
import org.springframework.security.acls.model.Acl;
|
|
||||||
import org.springframework.security.acls.model.AuditableAccessControlEntry;
|
|
||||||
import org.springframework.security.acls.model.ObjectIdentity;
|
|
||||||
import org.springframework.security.acls.model.Sid;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* {@link RuntimeHintsRegistrar} for ACL (Access Control List) classes.
|
|
||||||
*
|
|
||||||
* @author Josh Long
|
|
||||||
*/
|
|
||||||
class AclRuntimeHints implements RuntimeHintsRegistrar {
|
|
||||||
|
|
||||||
@Override
|
|
||||||
public void registerHints(RuntimeHints hints, @Nullable ClassLoader classLoader) {
|
|
||||||
registerAclDomainHints(hints);
|
|
||||||
registerJdbcSchemaHints(hints);
|
|
||||||
}
|
|
||||||
|
|
||||||
private void registerAclDomainHints(RuntimeHints hints) {
|
|
||||||
// Register core ACL domain types
|
|
||||||
Stream
|
|
||||||
.of(Acl.class, AccessControlEntry.class, AuditableAccessControlEntry.class, ObjectIdentity.class, Sid.class,
|
|
||||||
AclImpl.class, AccessControlEntry.class, AuditLogger.class, ObjectIdentityImpl.class,
|
|
||||||
PrincipalSid.class, GrantedAuthoritySid.class, BasePermission.class)
|
|
||||||
.forEach((c) -> hints.reflection()
|
|
||||||
.registerType(TypeReference.of(c),
|
|
||||||
(builder) -> builder.withMembers(MemberCategory.INVOKE_DECLARED_CONSTRUCTORS,
|
|
||||||
MemberCategory.INVOKE_DECLARED_METHODS, MemberCategory.ACCESS_DECLARED_FIELDS)));
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
private void registerJdbcSchemaHints(RuntimeHints hints) {
|
|
||||||
String[] sqlFiles = new String[] { "createAclSchema.sql", "createAclSchemaMySQL.sql",
|
|
||||||
"createAclSchemaOracle.sql", "createAclSchemaPostgres.sql", "createAclSchemaSqlServer.sql",
|
|
||||||
"createAclSchemaWithAclClassIdType.sql", "select.sql" };
|
|
||||||
for (String sqlFile : sqlFiles) {
|
|
||||||
Resource sqlResource = new ClassPathResource(sqlFile);
|
|
||||||
if (sqlResource.exists()) {
|
|
||||||
hints.resources().registerResource(sqlResource);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
/*
|
|
||||||
* Copyright 2004-present the original author or authors.
|
|
||||||
*
|
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
* you may not use this file except in compliance with the License.
|
|
||||||
* You may obtain a copy of the License at
|
|
||||||
*
|
|
||||||
* https://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
*
|
|
||||||
* Unless required by applicable law or agreed to in writing, software
|
|
||||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
* See the License for the specific language governing permissions and
|
|
||||||
* limitations under the License.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/**
|
|
||||||
* AOT and native image hint support for ACLs.
|
|
||||||
*/
|
|
||||||
@NullMarked
|
|
||||||
package org.springframework.security.acls.aot.hint;
|
|
||||||
|
|
||||||
import org.jspecify.annotations.NullMarked;
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user