-
Notifications
You must be signed in to change notification settings - Fork 6k
Issues: spring-projects/spring-security
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Make An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-feedback
We need additional information before we can continue
type: enhancement
A general enhancement
X509CertificateThumbprintValidator
configurable through JwtValidators
create APIs
in: oauth2
#17131
opened May 17, 2025 by
edmundham
Add possibility to customize JwkSource of NimbusJwtDecoder
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
#17046
opened May 6, 2025 by
marbon87
Loading…
NimbusJwtEncoder should simplify constructing with javax.security Keys
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
JwtTimestampsValidator can require exp and nbf claims
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Add support dpop customization
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Reactive implementation for DPoPAuthenticationProvider & related classes
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Remove deprecated implementations of OAuth2AccessTokenResponseClient
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Add support for nested user-name-attribute using dot notation
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-feedback
We need additional information before we can continue
type: enhancement
A general enhancement
#16857
opened Apr 1, 2025 by
yybmion
Loading…
Consider making UserInfo request opt-in instead of default in Spring Security 7
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: breaks-passivity
A change that breaks passivity with the previous release
type: enhancement
A general enhancement
Add Equals and HashCode methods for better comparison.
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
SupplierClientRegistrationRepository for reactive stack
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16750
opened Mar 17, 2025 by
bilak
OAuth2ResourceServerConfigurer#authenticationManagerResolver should override #jwt
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: ideal-for-contribution
An issue that we actively are looking for someone to help us with
type: enhancement
A general enhancement
#16406
opened Jan 13, 2025 by
jgrandja
Simplify Configuring Log In using Twitter / X v2 APIs
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
Default value for ClientRegistration redirect-uri
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
[Azure Oauth2] IllegalArgumentException: Attribute value for "xxx" is null
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: feedback-provided
Feedback has been provided
type: bug
A general bug
#16340
opened Dec 24, 2024 by
jloisel
Pass Http Request to OAuth2AuthorizationRequestResolver#authorizationRequestCustomizer
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16306
opened Dec 19, 2024 by
ZIRAKrezovic
Consider adding An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
PrincipalResolver
to ExchangeFilterFunctions
in: oauth2
NimbusJwtEncoder should simplify constructing with javax.security Keys
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16267
opened Dec 12, 2024 by
jzheaux
Support refreshing OIDC ID Token
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16253
opened Dec 10, 2024 by
filiphr
OidcBackChannelLogoutWebFilter returns an error for unauthenticated ajax requests
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: waiting-for-triage
An issue we've not yet triaged
type: bug
A general bug
#16073
opened Nov 12, 2024 by
katya-tis
Consider aligning OAuth 2.0 Access Token Response parsing in BodyExtractor
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#16001
opened Oct 25, 2024 by
sjohnr
Upgrade nimbus-jose-jwt:jar to 9.37.3 in Spring Security 5.8.x
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
status: feedback-provided
Feedback has been provided
type: dependency-upgrade
A dependency upgrade
#15951
opened Oct 18, 2024 by
blackat
Allow comma-delimited scopes in OAuth2 access token response
in: oauth2
An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
#15878
opened Oct 5, 2024 by
bfanyuk
Add An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
OAuth2AuthorizedClientManager
autoconfiguration without spring-boot-starter-web
dependency
in: oauth2
#15877
opened Oct 4, 2024 by
yvasyliev
Consider adding An issue in OAuth2 modules (oauth2-core, oauth2-client, oauth2-resource-server, oauth2-jose)
type: enhancement
A general enhancement
ClientRegistrationIdResolver
to ExchangeFilterFunction
s
in: oauth2
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.