⭐ New Features
- Fix Spring initializr link in 'Getting Spring Security' #14375
- Refactor: Remove Irrelevant Documentation Lines #14374
- Typo fix in configuration.adoc #14372
- Updated the Configuration examples in docs #14391
🪲 Bug Fixes
- "Span wasn't started - an observation must be started (not only created)" (Micrometer) due to observation handling in Spring Security Web? #14445
HandlerMappingIntrospectorRequestTransformer
is registered twice in AOT #14362OAuth2AuthorizationExchange
is not serializable #14402WebTestUtilsTestRuntimeHints
should implementRuntimeHintsRegistrar
#14399- Application context fails to load: Couldn't find FilterChainProxy #14370
- Cannot configure
SecurityContextRepository
inCasAuthenticationFilter
#14529 - Documentation about configuring SecuritySocketAcceptorInterceptor in Spring Boot is confusing #14347
- Fix broken sample code in Authorize HttpServletRequests #14386
- Fix command in CONTRIBUTING.adoc #14489
- Missing native-image reflection hint for
HandlerMappingIntrospectorCachFilterFactoryBean
#14359 - Missing native-image reflection hint for CsrfTokenRequestAttributeHandler$SupplierCsrfToken #14397
- ReactiveMethodSecurityConfiguration is initialized prematurely when the context contains a BeanPostProcessor #14349
- SAML relying party logout filter is always ordered last #14550
- Typo: Update ldap.adoc #14509
- Typo: Update session-management.adoc #14515
- Unexpected Exception Handling in NimbusReactiveJwtDecoder decode Method #14495
- X-Xss-Protection header "1; mode=block" differs in Servlet and Reactive #14345
🔨 Dependency Upgrades
- Bump Gamesight/slack-workflow-status from 1.2.0 to 1.3.0 #14581
- Bump Gradle Wrapper from 8.5 to 8.6 #14540
- Bump gradle/gradle-build-action from 2 to 3 #14500
- Bump io-spring-javaformat from 0.0.40 to 0.0.41 #14436
- Bump io.mockk:mockk from 1.13.8 to 1.13.9 #14413
- Bump io.projectreactor:reactor-bom from 2022.0.14 to 2022.0.15 #14428
- Bump io.projectreactor:reactor-bom from 2022.0.15 to 2022.0.16 #14611
- Bump io.spring.ge.conventions from 0.0.14 to 0.0.15 #14465
- Bump org-aspectj from 1.9.21 to 1.9.21.1 #14606
- Bump org-eclipse-jetty from 11.0.18 to 11.0.19 #14355
- Bump org-eclipse-jetty from 11.0.19 to 11.0.20 #14519
- Bump org.apereo.cas.client:cas-client-core from 4.0.3 to 4.0.4 #14437
- Bump org.slf4j:slf4j-api from 2.0.10 to 2.0.11 #14421
- Bump org.slf4j:slf4j-api from 2.0.11 to 2.0.12 #14555
- Bump org.slf4j:slf4j-api from 2.0.9 to 2.0.10 #14389
- Bump org.springframework:spring-framework-bom from 6.0.15 to 6.0.16 #14443
- Bump org.springframework:spring-framework-bom from 6.0.16 to 6.0.17 #14621
- Bump slackapi/slack-github-action from 1.24.0 to 1.25.0 #14499
- Bump spring-io/spring-github-workflows from eaf17a1890b1ef1b337f015d6eb263baaf8c6dab to 1e8b0587a1f4f01697f9753fa3339c3e0d30f396 #14580
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Siddharth1605, @acktsap, @boulce, @dependabot[bot], @github-actions[bot], @kcsurapaneni, @nkilchenmann, and @ty-v1