github spring-projects/spring-security 6.2.2

latest releases: 6.4.0-M4, 6.4.0-M3, 6.3.3...
7 months ago

⭐ New Features

  • Configuration examples in docs are out of date #14392

🪲 Bug Fixes

  • "Span wasn't started - an observation must be started (not only created)" (Micrometer) due to observation handling in Spring Security Web? #14568
  • HandlerMappingIntrospectorRequestTransformer is registered twice in AOT #14367
  • OAuth2AuthorizationExchange is not serializable #14405
  • WebTestUtilsTestRuntimeHints should implement RuntimeHintsRegistrar #14468
  • Application context fails to load: Couldn't find FilterChainProxy #14380
  • Back-Channel Logout should use localhost for internal logout request #14553
  • Cannot configure SecurityContextRepository in CasAuthenticationFilter #14536
  • Documentation about configuring SecuritySocketAcceptorInterceptor in Spring Boot is confusing #14348
  • fix typo in anonymous.adoc #14424
  • fix: typo in Authentication Architecture ProviderManager #14448
  • Missing native-image reflection hint for HandlerMappingIntrospectorCachFilterFactoryBean #14377
  • Missing native-image reflection hint for CsrfTokenRequestAttributeHandler$SupplierCsrfToken #14470
  • ReactiveMethodSecurityConfiguration is initialized prematurely when the context contains a BeanPostProcessor #14350
  • SAML relying party logout filter is always ordered last #14551
  • Spring Security 6.2 defaults to InMemoryOidcSessionRegistry causing memory leaks in distributed systems with external session storage #14558
  • Test using @WithMockUser fails with 401 UNAUTHORIZED with 3.2 #14207
  • Typo: Update authorize-http-requests.adoc #14563
  • Unexpected Exception Handling in NimbusReactiveJwtDecoder decode Method #14496
  • X-Xss-Protection header "1; mode=block" differs in Servlet and Reactive #14346

🔨 Dependency Upgrades

  • Bump com.fasterxml.jackson:jackson-bom from 2.15.3 to 2.15.4 #14617
  • Bump Gamesight/slack-workflow-status from 1.2.0 to 1.3.0 #14582
  • Bump Gradle Wrapper from 8.5 to 8.6 #14547
  • Bump gradle/gradle-build-action from 2 to 3 #14503
  • Bump io-spring-javaformat from 0.0.40 to 0.0.41 #14439
  • Bump io.micrometer:micrometer-observation from 1.12.1 to 1.12.2 #14429
  • Bump io.micrometer:micrometer-observation from 1.12.2 to 1.12.3 #14589
  • Bump io.mockk:mockk from 1.13.8 to 1.13.9 #14412
  • Bump io.projectreactor:reactor-bom from 2023.0.1 to 2023.0.2 #14430
  • Bump io.projectreactor:reactor-bom from 2023.0.2 to 2023.0.3 #14612
  • Bump io.spring.ge.conventions from 0.0.14 to 0.0.15 #14463
  • Bump org-aspectj from 1.9.21 to 1.9.21.1 #14605
  • Bump org-eclipse-jetty from 11.0.18 to 11.0.19 #14354
  • Bump org-eclipse-jetty from 11.0.19 to 11.0.20 #14518
  • Bump org.apereo.cas.client:cas-client-core from 4.0.3 to 4.0.4 #14440
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.21 to 1.9.22 #14364
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.21 to 1.9.22 #14363
  • Bump org.junit:junit-bom from 5.10.1 to 5.10.2 #14543
  • Bump org.slf4j:slf4j-api from 2.0.10 to 2.0.11 #14422
  • Bump org.slf4j:slf4j-api from 2.0.11 to 2.0.12 #14554
  • Bump org.slf4j:slf4j-api from 2.0.9 to 2.0.10 #14387
  • Bump org.springframework.data:spring-data-bom from 2023.1.1 to 2023.1.2 #14455
  • Bump org.springframework.data:spring-data-bom from 2023.1.2 to 2023.1.3 #14624
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.1 to 3.2.2 #14616
  • Bump org.springframework:spring-framework-bom from 6.1.2 to 6.1.3 #14454
  • Bump org.springframework:spring-framework-bom from 6.1.3 to 6.1.4 #14615
  • Bump slackapi/slack-github-action from 1.24.0 to 1.25.0 #14504
  • Bump spring-io/spring-github-workflows from eaf17a1890b1ef1b337f015d6eb263baaf8c6dab to 1e8b0587a1f4f01697f9753fa3339c3e0d30f396 #14583

❤️ Contributors

Thank you to all the contributors who worked on this release:

@Amitmahato, @andreasbuechel, @boulce, and @dependabot[bot]

Don't miss a new spring-security release

NewReleases is sending notifications on new releases.