Madhura Bhave
d9d161cd6b
Allow previously authorized users to access the error page
...
Prior to this commit, the `ErrorPageSecurityFilter` verified if
access to the error page was allowed by invoking the
`WebInvocationPrivilegeEvaluator` with the Authentication from the
`SecurityContextHolder`.
This meant that access to the error page was denied for a `null` Authentication
or `AnonymousAuthenticationToken` in cases where the error page required
authenticated access. This prevented authorized users from accessing the
error page in case the Authentication wasn't retrievable for the error dispatch,
which is the case for `@Transient` authentication or stateless session policy.
This commit updates the `ErrorPageSecurityFilter` to check access to the error page
only if the error is an authn or authz error in cases where an authentication object
is not found in the SecurityContextHolder. This makes the error response consistent
when bad credentials or no credentials are used while also allowing access to previously
authorized users.
Fixes gh-28953
3 years ago
Stephane Nicoll
c975fbc286
Merge branch '2.7.x'
3 years ago
Stephane Nicoll
64dd1f86c0
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29104
3 years ago
Stephane Nicoll
c077ebecf7
Merge branch '2.5.x' into 2.6.x
...
Closes gh-29103
3 years ago
Andy Wilkinson
2fec06ac7e
Find annotation without initializing factory beans
...
Closes gh-28977
3 years ago
Brian Clozel
d13441c009
Merge branch '2.7.x'
...
Closes gh-29014
3 years ago
Brian Clozel
b04f7904ff
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29013
3 years ago
Brian Clozel
1c35ec2c3c
Merge branch '2.5.x' into 2.6.x
...
Closes gh-29012
3 years ago
Brian Clozel
5d0206320a
Upgrade to Logback 1.2.9
...
Closes gh-29011
3 years ago
Stephane Nicoll
63121b451f
Upgrade to Gradle 7.3.2
...
Closes gh-29100
3 years ago
Stephane Nicoll
b9057f1957
Merge branch '2.7.x'
3 years ago
Stephane Nicoll
de383fcee0
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29099
3 years ago
Stephane Nicoll
bcaa59ce73
Merge branch '2.5.x' into 2.6.x
...
Closes gh-29098
3 years ago
Stephane Nicoll
614d34195a
Merge pull request #29094 from An1s9n
...
* pr/29094:
Polish CacheManager customization section in reference doc
Closes gh-29094
3 years ago
Pavel Anisimov
415c58e21b
Polish CacheManager customization section in reference doc
...
See gh-29094
3 years ago
Stephane Nicoll
62d8f0db78
Merge branch '2.7.x'
3 years ago
Stephane Nicoll
a05714ad9f
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29097
3 years ago
Stephane Nicoll
10362a9315
Merge branch '2.5.x' into 2.6.x
...
Closes gh-29096
3 years ago
Stephane Nicoll
8c9d398422
Test our Gradle plugin against Gradle 7.3.2
...
Closes gh-29093
3 years ago
Phillip Webb
77c1f5aa27
Merge branch '2.7.x'
3 years ago
Phillip Webb
1015df088d
Merge branch '2.6.x' into 2.7.x
3 years ago
Phillip Webb
587d6fa309
Polish
3 years ago
Phillip Webb
7981a82785
Merge branch '2.7.x'
3 years ago
Phillip Webb
9c36682fe7
Merge branch '2.6.x' into 2.7.x
3 years ago
Phillip Webb
f676602c96
Merge branch '2.5.x' into 2.6.x
3 years ago
Phillip Webb
783981ba98
Merge branch '2.4.x' into 2.5.x
3 years ago
Phillip Webb
d336a96b7f
Update web.xml xsd references to for 3.1 version
...
See gh-29075
3 years ago
Phillip Webb
003fb229fd
Merge branch '2.7.x'
3 years ago
Phillip Webb
a74b563b49
Merge branch '2.6.x' into 2.7.x
3 years ago
Phillip Webb
a6a5b81dd0
Merge branch '2.5.x' into 2.6.x
3 years ago
Phillip Webb
f3bcbca841
Update copyright year of changed files
3 years ago
Scott Frederick
b4cdd37e63
Merge branch '2.7.x'
3 years ago
Scott Frederick
4cad4851da
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29088
3 years ago
Scott Frederick
92b096abbf
Fix message interpolation when code is used as default message
...
When `setUseCodeAsDefaultMessage(true)` was set on a message source,
attempting to interpolate the default message returned from the message
source would result in the code being unusable by upstream message
resolvers.
Fixes gh-28930
3 years ago
Stephane Nicoll
4d0b583b46
Merge branch '2.7.x'
3 years ago
Stephane Nicoll
3039272a70
Merge branch '2.6.x' into 2.7.x
3 years ago
Stephane Nicoll
6555ad404e
Merge branch '2.5.x' into 2.6.x
3 years ago
Stephane Nicoll
f2efe56a18
Upgrade to Spring Framework 5.3.14
3 years ago
Stephane Nicoll
a7a37f4ad6
Upgrade to Spring Framework 5.3.14
...
Closes gh-28970
3 years ago
Stephane Nicoll
b8bf2cbbc7
Upgrade to Spring Framework 5.3.14
...
Closes gh-28961
3 years ago
Stephane Nicoll
75d2c36846
Merge branch '2.7.x'
3 years ago
Stephane Nicoll
63427b77d1
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29086
3 years ago
Stephane Nicoll
55859ea64c
Stop accessing the datasource if initialization mode is set to never
...
Closes gh-28931
3 years ago
Phillip Webb
c0023118a9
Merge branch '2.7.x'
...
Closes gh-29079
3 years ago
Phillip Webb
b85b6b06a6
Merge branch '2.6.x' into 2.7.x
...
Closes gh-29078
3 years ago
Phillip Webb
6e01c3edbe
Merge branch '2.5.x' into 2.6.x
...
Closes gh-29077
3 years ago
Phillip Webb
17363d1b3a
Merge branch '2.4.x' into 2.5.x
...
Closes gh-29076
3 years ago
Phillip Webb
1749c893dc
Update web-app version to 3.1
...
Update the web-app version specified in `web.xml` to 3.1 in order to
make Eclipse happy.
Closes gh-29075
3 years ago
Scott Frederick
07243539bd
Remove unused import
...
See gh-29029
3 years ago
Scott Frederick
caf49783d4
Merge branch '2.7.x'
3 years ago