-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Issues: spring-projects/spring-security
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Add Support DPoP Customization
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Ensure ID Token is updated after refresh token (Reactive)
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Introduce An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: bug
A general bug
DPoPAuthenticationFilter
to avoid conflict with other AuthenticationFilter
in: oauth2
#17186
opened May 29, 2025 by
therepanic
Loading…
DPoP filter is ignored when another AuthenticationFilter is present
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: bug
A general bug
NimbusJwtEncoder should simplify constructing with javax.security Keys
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-feedback
We need additional information before we can continue
type: enhancement
A general enhancement
Add support dpop customization
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Reactive implementation for DPoPAuthenticationProvider & related classes
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Remove deprecated implementations of OAuth2AccessTokenResponseClient
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Add support for nested user-name-attribute using dot notation
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: feedback-provided
Feedback has been provided
type: enhancement
A general enhancement
#16857
opened Apr 1, 2025 by
yybmion
Loading…
Consider making UserInfo request opt-in instead of default in Spring Security 7
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
SupplierClientRegistrationRepository for reactive stack
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16750
opened Mar 17, 2025 by
bilak
OAuth2ResourceServerConfigurer#authenticationManagerResolver should override #jwt
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: ideal-for-contribution
An issue that we actively are looking for someone to help us with
type: enhancement
A general enhancement
#16406
opened Jan 13, 2025 by
jgrandja
Simplify Configuring Log In using Twitter / X v2 APIs
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Default value for ClientRegistration redirect-uri
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
[Azure Oauth2] IllegalArgumentException: Attribute value for "xxx" is null
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: feedback-provided
Feedback has been provided
type: bug
A general bug
#16340
opened Dec 24, 2024 by
jloisel
Pass Http Request to OAuth2AuthorizationRequestResolver#authorizationRequestCustomizer
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16306
opened Dec 19, 2024 by
ZIRAKrezovic
Consider adding An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
PrincipalResolver
to ExchangeFilterFunctions
in: oauth2
NimbusJwtEncoder should simplify constructing with javax.security Keys
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16267
opened Dec 12, 2024 by
jzheaux
Support refreshing OIDC ID Token
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16253
opened Dec 10, 2024 by
filiphr
OidcBackChannelLogoutWebFilter returns an error for unauthenticated ajax requests
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-triage
An issue we've not yet triaged
type: bug
A general bug
#16073
opened Nov 12, 2024 by
katya-tis
Consider aligning OAuth 2.0 Access Token Response parsing in BodyExtractor
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16001
opened Oct 25, 2024 by
sjohnr
Upgrade nimbus-jose-jwt:jar to 9.37.3 in Spring Security 5.8.x
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: feedback-provided
Feedback has been provided
type: dependency-upgrade
A dependency upgrade
#15951
opened Oct 18, 2024 by
blackat
Allow comma-delimited scopes in OAuth2 access token response
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#15878
opened Oct 5, 2024 by
bfanyuk
Add An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
OAuth2AuthorizedClientManager
autoconfiguration without spring-boot-starter-web
dependency
in: oauth2
#15877
opened Oct 4, 2024 by
yvasyliev
Consider adding An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
ClientRegistrationIdResolver
to ExchangeFilterFunction
s
in: oauth2
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.