github spring-projects/spring-security 5.4.10

latest releases: 6.4.0-M4, 6.4.0-M3, 6.3.3...
2 years ago

🪲 Bug Fixes

  • StaticServerHttpHeadersWriter should work with case-insensitive header names #10583
  • Invalid_request failures in JwtTokenValidators are always turned into invalid_token errors #10562
  • MissingCsrfTokenException message is misleading when not storing the CSRF tokens in the session #10532
  • Documentation has wrong code example in the 'Customizing OpenSAML’s AuthnRequest Instance' section #10528
  • Multi-tenancy Documentation - com.nimbusds.jwt.proc.JWTProcessor does not have a setJWTClaimSetJWSKeySelector method #10521
  • Multi-tenancy Documentation - JwtDecoder sample has multiple errors #10517
  • Oauth2 Resource Server will not retry on first failure with Multi-tenancy #10485
  • WebInvocationPrivilegeEvaluator does not provide a way to pass a ServletContext #10437

Don't miss a new spring-security release

NewReleases is sending notifications on new releases.