Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: spring-projects/spring-authorization-server
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 1.3.0
Choose a base ref
...
head repository: spring-projects/spring-authorization-server
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 1.3.1
Choose a head ref

Commits on May 21, 2024

  1. Next development version

    github-actions[bot] committed May 21, 2024

    Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
    Copy the full SHA
    c59e496 View commit details

Commits on May 22, 2024

  1. Remove 1.1.x from release-scheduler.yml

    jgrandja committed May 22, 2024

    Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
    Copy the full SHA
    b3249ff View commit details
  2. Apply Spring checkstyle conventions

    Issue gh-1624
    jgrandja committed May 22, 2024

    Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
    Copy the full SHA
    1dd0ab0 View commit details
  3. Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
    Copy the full SHA
    9c45484 View commit details
  4. Fix checkstyle violations for test module

    Issue gh-1624
    jgrandja committed May 22, 2024
    Copy the full SHA
    00e7d67 View commit details

Commits on May 23, 2024

  1. Copy the full SHA
    43fbafe View commit details
  2. Copy the full SHA
    365ae4e View commit details
  3. Fix checkstyle violations for test module in 1.2.x

    Issue gh-1624
    jgrandja committed May 23, 2024
    Copy the full SHA
    9d336eb View commit details
  4. Merge branch '1.2.x'

    jgrandja committed May 23, 2024
    Copy the full SHA
    12b71ea View commit details
  5. Copy the full SHA
    fa59682 View commit details
  6. Fix checkstyle violations for test module in 1.3.x

    Issue gh-1624
    jgrandja committed May 23, 2024
    Copy the full SHA
    448a782 View commit details
  7. Update copyright year in reference doc

    jgrandja committed May 23, 2024
    Copy the full SHA
    1c484db View commit details

Commits on Jun 5, 2024

  1. Fix AOT hints for OAuth 2.0 Token Exchange

    Closes gh-1630
    nwholloway authored and jgrandja committed Jun 5, 2024
    Copy the full SHA
    25b70bc View commit details

Commits on Jun 12, 2024

  1. X509 client certificate authentication triggers when client id is pro…

    …vided
    
    Closes gh-1635
    jgrandja committed Jun 12, 2024
    Copy the full SHA
    e3c6eff View commit details

Commits on Jun 17, 2024

  1. Update link to code of conduct

    jgrandja committed Jun 17, 2024
    Copy the full SHA
    9e4a4f0 View commit details
  2. Merge branch '1.1.x' into 1.2.x

    jgrandja committed Jun 17, 2024
    Copy the full SHA
    4fc30a2 View commit details
  3. Merge branch '1.2.x'

    jgrandja committed Jun 17, 2024
    Copy the full SHA
    b8cbf0a View commit details
  4. Update to Spring Framework 6.1.9

    Closes gh-1649
    jgrandja committed Jun 17, 2024
    Copy the full SHA
    d1acbd7 View commit details
  5. Update to Spring Security 6.3.1

    Closes gh-1650
    jgrandja committed Jun 17, 2024
    Copy the full SHA
    90b3d50 View commit details
  6. Update to nimbus-jose-jwt 9.39.3

    Closes gh-1651
    jgrandja committed Jun 17, 2024
    Copy the full SHA
    c63fe1f View commit details
  7. Update to org.hsqldb:hsqldb 2.7.3

    Closes gh-1652
    jgrandja committed Jun 17, 2024
    Copy the full SHA
    567478c View commit details

Commits on Jun 18, 2024

  1. Release 1.3.1

    github-actions[bot] committed Jun 18, 2024
    Copy the full SHA
    d8aae6a View commit details
Showing with 1,847 additions and 1,897 deletions.
  1. +1 −1 .github/workflows/release-scheduler.yml
  2. +0 −44 CODE_OF_CONDUCT.adoc
  3. +1 −3 CONTRIBUTING.adoc
  4. +1 −2 README.adoc
  5. +1 −1 buildSrc/build.gradle
  6. +2 −2 dependencies/spring-authorization-server-dependencies.gradle
  7. +1 −1 docs/modules/ROOT/pages/index.adoc
  8. +8 −0 etc/checkstyle/checkstyle-suppressions.xml
  9. +12 −45 etc/checkstyle/checkstyle.xml
  10. +1 −1 etc/checkstyle/header.txt
  11. +0 −20 etc/checkstyle/suppressions.xml
  12. +3 −3 gradle.properties
  13. +7 −4 ...ringframework/security/oauth2/server/authorization/AbstractOAuth2AuthorizationServerMetadata.java
  14. +1 −1 ...ringframework/security/oauth2/server/authorization/InMemoryOAuth2AuthorizationConsentService.java
  15. +16 −9 .../org/springframework/security/oauth2/server/authorization/InMemoryOAuth2AuthorizationService.java
  16. +11 −11 ...g/springframework/security/oauth2/server/authorization/JdbcOAuth2AuthorizationConsentService.java
  17. +71 −71 ...java/org/springframework/security/oauth2/server/authorization/JdbcOAuth2AuthorizationService.java
  18. +3 −2 ...r/src/main/java/org/springframework/security/oauth2/server/authorization/OAuth2Authorization.java
  19. +2 −2 ...a/org/springframework/security/oauth2/server/authorization/OAuth2AuthorizationConsentService.java
  20. +2 −2 ...a/org/springframework/security/oauth2/server/authorization/OAuth2AuthorizationServerMetadata.java
  21. +4 −4 .../main/java/org/springframework/security/oauth2/server/authorization/OAuth2TokenIntrospection.java
  22. +6 −0 ...erver/src/main/java/org/springframework/security/oauth2/server/authorization/OAuth2TokenType.java
  23. +7 −7 ...y/oauth2/server/authorization/aot/hint/OAuth2AuthorizationServerBeanRegistrationAotProcessor.java
  24. +1 −1 ...security/oauth2/server/authorization/authentication/JwtClientAssertionAuthenticationProvider.java
  25. +3 −5 ...ity/oauth2/server/authorization/authentication/OAuth2AuthorizationCodeAuthenticationProvider.java
  26. +2 −2 ...th2/server/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationProvider.java
  27. +3 −3 ...oauth2/server/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationToken.java
  28. +4 −6 .../oauth2/server/authorization/authentication/OAuth2AuthorizationConsentAuthenticationProvider.java
  29. +2 −2 ...ity/oauth2/server/authorization/authentication/OAuth2AuthorizationConsentAuthenticationToken.java
  30. +1 −1 ...urity/oauth2/server/authorization/authentication/OAuth2AuthorizationGrantAuthenticationToken.java
  31. +1 −1 ...ramework/security/oauth2/server/authorization/authentication/OAuth2ClientAuthenticationToken.java
  32. +2 −4 ...ity/oauth2/server/authorization/authentication/OAuth2ClientCredentialsAuthenticationProvider.java
  33. +1 −1 ...curity/oauth2/server/authorization/authentication/OAuth2ClientCredentialsAuthenticationToken.java
  34. +10 −10 ...2/server/authorization/authentication/OAuth2DeviceAuthorizationConsentAuthenticationProvider.java
  35. +1 −1 ...uth2/server/authorization/authentication/OAuth2DeviceAuthorizationConsentAuthenticationToken.java
  36. +2 −4 ...2/server/authorization/authentication/OAuth2DeviceAuthorizationRequestAuthenticationProvider.java
  37. +3 −3 ...uth2/server/authorization/authentication/OAuth2DeviceAuthorizationRequestAuthenticationToken.java
  38. +3 −5 ...k/security/oauth2/server/authorization/authentication/OAuth2DeviceCodeAuthenticationProvider.java
  39. +3 −3 ...ty/oauth2/server/authorization/authentication/OAuth2DeviceVerificationAuthenticationProvider.java
  40. +1 −1 ...urity/oauth2/server/authorization/authentication/OAuth2DeviceVerificationAuthenticationToken.java
  41. +2 −4 ...security/oauth2/server/authorization/authentication/OAuth2RefreshTokenAuthenticationProvider.java
  42. +1 −1 ...rk/security/oauth2/server/authorization/authentication/OAuth2RefreshTokenAuthenticationToken.java
  43. +2 −4 ...ecurity/oauth2/server/authorization/authentication/OAuth2TokenExchangeAuthenticationProvider.java
  44. +3 −3 ...k/security/oauth2/server/authorization/authentication/OAuth2TokenExchangeAuthenticationToken.java
  45. +1 −1 ...y/oauth2/server/authorization/authentication/OAuth2TokenExchangeCompositeAuthenticationToken.java
  46. +2 −4 ...ty/oauth2/server/authorization/authentication/OAuth2TokenIntrospectionAuthenticationProvider.java
  47. +1 −1 ...urity/oauth2/server/authorization/authentication/OAuth2TokenIntrospectionAuthenticationToken.java
  48. +2 −4 ...urity/oauth2/server/authorization/authentication/OAuth2TokenRevocationAuthenticationProvider.java
  49. +2 −2 ...mework/security/oauth2/server/authorization/authentication/X509SelfSignedCertificateVerifier.java
  50. +2 −2 ...ringframework/security/oauth2/server/authorization/client/InMemoryRegisteredClientRepository.java
  51. +19 −19 ...g/springframework/security/oauth2/server/authorization/client/JdbcRegisteredClientRepository.java
  52. +2 −2 ...c/main/java/org/springframework/security/oauth2/server/authorization/client/RegisteredClient.java
  53. +1 −1 ...a/org/springframework/security/oauth2/server/authorization/client/RegisteredClientRepository.java
  54. +2 −2 ...ver/authorization/config/annotation/web/configuration/OAuth2AuthorizationServerConfiguration.java
  55. +3 −0 .../oauth2/server/authorization/config/annotation/web/configurers/DefaultOAuth2TokenCustomizers.java
  56. +7 −6 ...server/authorization/config/annotation/web/configurers/OAuth2AuthorizationEndpointConfigurer.java
  57. +5 −7 ...2/server/authorization/config/annotation/web/configurers/OAuth2AuthorizationServerConfigurer.java
  58. +5 −4 ...zation/config/annotation/web/configurers/OAuth2AuthorizationServerMetadataEndpointConfigurer.java
  59. +10 −8 .../server/authorization/config/annotation/web/configurers/OAuth2ClientAuthenticationConfigurer.java
  60. +1 −1 ...security/oauth2/server/authorization/config/annotation/web/configurers/OAuth2ConfigurerUtils.java
  61. +6 −5 .../authorization/config/annotation/web/configurers/OAuth2DeviceAuthorizationEndpointConfigurer.java
  62. +6 −5 ...r/authorization/config/annotation/web/configurers/OAuth2DeviceVerificationEndpointConfigurer.java
  63. +4 −5 .../oauth2/server/authorization/config/annotation/web/configurers/OAuth2TokenEndpointConfigurer.java
  64. +6 −5 ...r/authorization/config/annotation/web/configurers/OAuth2TokenIntrospectionEndpointConfigurer.java
  65. +6 −5 ...rver/authorization/config/annotation/web/configurers/OAuth2TokenRevocationEndpointConfigurer.java
  66. +6 −5 ...ver/authorization/config/annotation/web/configurers/OidcClientRegistrationEndpointConfigurer.java
  67. +3 −2 ...mework/security/oauth2/server/authorization/config/annotation/web/configurers/OidcConfigurer.java
  68. +4 −5 ...y/oauth2/server/authorization/config/annotation/web/configurers/OidcLogoutEndpointConfigurer.java
  69. +5 −4 .../authorization/config/annotation/web/configurers/OidcProviderConfigurationEndpointConfigurer.java
  70. +6 −5 ...oauth2/server/authorization/config/annotation/web/configurers/OidcUserInfoEndpointConfigurer.java
  71. +1 −1 ...rg/springframework/security/oauth2/server/authorization/http/converter/HttpMessageConverters.java
  72. +5 −4 ...in/java/org/springframework/security/oauth2/server/authorization/oidc/OidcClientRegistration.java
  73. +5 −4 ...java/org/springframework/security/oauth2/server/authorization/oidc/OidcProviderConfiguration.java
  74. +1 −1 .../security/oauth2/server/authorization/oidc/authentication/OidcUserInfoAuthenticationProvider.java
  75. +15 −10 ...y/oauth2/server/authorization/oidc/converter/OidcClientRegistrationRegisteredClientConverter.java
  76. +5 −5 ...y/oauth2/server/authorization/oidc/converter/RegisteredClientOidcClientRegistrationConverter.java
  77. +1 −1 ...ringframework/security/oauth2/server/authorization/oidc/http/converter/HttpMessageConverters.java
  78. +1 −1 ...y/oauth2/server/authorization/oidc/http/converter/OidcClientRegistrationHttpMessageConverter.java
  79. +2 −2 ...framework/security/oauth2/server/authorization/oidc/web/OidcClientRegistrationEndpointFilter.java
  80. +4 −1 ...main/java/org/springframework/security/oauth2/server/authorization/settings/AbstractSettings.java
  81. +2 −2 ...rg/springframework/security/oauth2/server/authorization/settings/AuthorizationServerSettings.java
  82. +2 −2 ...c/main/java/org/springframework/security/oauth2/server/authorization/settings/ClientSettings.java
  83. +4 −2 ...rc/main/java/org/springframework/security/oauth2/server/authorization/settings/TokenSettings.java
  84. +4 −2 ...er/src/main/java/org/springframework/security/oauth2/server/authorization/token/JwtGenerator.java
  85. +1 −0 ...ain/java/org/springframework/security/oauth2/server/authorization/token/OAuth2TokenClaimsSet.java
  86. +1 −1 ...in/java/org/springframework/security/oauth2/server/authorization/token/OAuth2TokenCustomizer.java
  87. +1 −1 ...ain/java/org/springframework/security/oauth2/server/authorization/token/OAuth2TokenGenerator.java
  88. +3 −1 ...rc/main/java/org/springframework/security/oauth2/server/authorization/web/DefaultConsentPage.java
  89. +4 −5 ...java/org/springframework/security/oauth2/server/authorization/web/NimbusJwkSetEndpointFilter.java
  90. +3 −3 ...g/springframework/security/oauth2/server/authorization/web/OAuth2AuthorizationEndpointFilter.java
  91. +2 −2 ...rg/springframework/security/oauth2/server/authorization/web/OAuth2ClientAuthenticationFilter.java
  92. +2 −2 ...ingframework/security/oauth2/server/authorization/web/OAuth2DeviceVerificationEndpointFilter.java
  93. +1 −1 ...ingframework/security/oauth2/server/authorization/web/OAuth2TokenIntrospectionEndpointFilter.java
  94. +1 −1 ...springframework/security/oauth2/server/authorization/web/OAuth2TokenRevocationEndpointFilter.java
  95. +0 −1 ...erver/authorization/web/authentication/OAuth2AccessTokenResponseAuthenticationSuccessHandler.java
  96. +4 −4 ...erver/authorization/web/authentication/OAuth2AuthorizationCodeRequestAuthenticationConverter.java
  97. +1 −2 ...urity/oauth2/server/authorization/web/authentication/OAuth2ErrorAuthenticationFailureHandler.java
  98. +6 −2 .../oauth2/server/authorization/web/authentication/X509ClientCertificateAuthenticationConverter.java
  99. +17 −19 ...ingframework/security/oauth2/server/authorization/JdbcOAuth2AuthorizationConsentServiceTests.java
  100. +124 −145 ...org/springframework/security/oauth2/server/authorization/JdbcOAuth2AuthorizationServiceTests.java
  101. +1 −1 ...ava/org/springframework/security/oauth2/server/authorization/OAuth2AuthorizationConsentTests.java
  102. +9 −9 .../springframework/security/oauth2/server/authorization/OAuth2AuthorizationServerMetadataTests.java
  103. +4 −1 .../test/java/org/springframework/security/oauth2/server/authorization/TestOAuth2Authorizations.java
  104. +45 −45 .../security/oauth2/server/authorization/authentication/ClientSecretAuthenticationProviderTests.java
  105. +27 −27 ...ity/oauth2/server/authorization/authentication/JwtClientAssertionAuthenticationProviderTests.java
  106. +6 −6 ...rk/security/oauth2/server/authorization/authentication/JwtClientAssertionDecoderFactoryTests.java
  107. +5 −5 ...ecurity/oauth2/server/authorization/authentication/OAuth2AccessTokenAuthenticationTokenTests.java
  108. +59 −59 ...auth2/server/authorization/authentication/OAuth2AuthorizationCodeAuthenticationProviderTests.java
  109. +81 −81 ...erver/authorization/authentication/OAuth2AuthorizationCodeRequestAuthenticationProviderTests.java
  110. +1 −1 ...th2/server/authorization/authentication/OAuth2AuthorizationConsentAuthenticationContextTests.java
  111. +79 −79 ...h2/server/authorization/authentication/OAuth2AuthorizationConsentAuthenticationProviderTests.java
  112. +12 −12 ...auth2/server/authorization/authentication/OAuth2ClientCredentialsAuthenticationProviderTests.java
  113. +38 −29 ...ver/authorization/authentication/OAuth2DeviceAuthorizationConsentAuthenticationProviderTests.java
  114. +9 −9 ...ver/authorization/authentication/OAuth2DeviceAuthorizationRequestAuthenticationProviderTests.java
  115. +34 −28 ...urity/oauth2/server/authorization/authentication/OAuth2DeviceCodeAuthenticationProviderTests.java
  116. +22 −18 ...uth2/server/authorization/authentication/OAuth2DeviceVerificationAuthenticationProviderTests.java
  117. +50 −50 ...ity/oauth2/server/authorization/authentication/OAuth2RefreshTokenAuthenticationProviderTests.java
  118. +30 −30 ...ty/oauth2/server/authorization/authentication/OAuth2TokenExchangeAuthenticationProviderTests.java
  119. +15 −15 ...uth2/server/authorization/authentication/OAuth2TokenIntrospectionAuthenticationProviderTests.java
  120. +9 −9 .../oauth2/server/authorization/authentication/OAuth2TokenRevocationAuthenticationProviderTests.java
  121. +42 −42 .../security/oauth2/server/authorization/authentication/PublicClientAuthenticationProviderTests.java
  122. +41 −41 .../oauth2/server/authorization/authentication/X509ClientCertificateAuthenticationProviderTests.java
  123. +4 −4 ...ingframework/security/oauth2/server/authorization/client/JdbcRegisteredClientRepositoryTests.java
  124. +47 −48 ...t/java/org/springframework/security/oauth2/server/authorization/client/RegisteredClientTests.java
  125. +4 −1 ...t/java/org/springframework/security/oauth2/server/authorization/client/TestRegisteredClients.java
  126. +1 −1 ...rver/authorization/config/annotation/web/configuration/RegisterMissingBeanPostProcessorTests.java
  127. +3 −4 ...server/authorization/config/annotation/web/configurers/AuthorizationServerContextFilterTests.java
  128. +4 −4 ...h2/server/authorization/config/annotation/web/configurers/DefaultOAuth2TokenCustomizersTests.java
  129. +4 −4 ...framework/security/oauth2/server/authorization/config/annotation/web/configurers/JwkSetTests.java
  130. +34 −34 ...th2/server/authorization/config/annotation/web/configurers/OAuth2AuthorizationCodeGrantTests.java
  131. +6 −6 ...erver/authorization/config/annotation/web/configurers/OAuth2AuthorizationServerMetadataTests.java
  132. +44 −23 ...th2/server/authorization/config/annotation/web/configurers/OAuth2ClientCredentialsGrantTests.java
  133. +3 −3 ...ity/oauth2/server/authorization/config/annotation/web/configurers/OAuth2DeviceCodeGrantTests.java
  134. +7 −8 ...y/oauth2/server/authorization/config/annotation/web/configurers/OAuth2RefreshTokenGrantTests.java
  135. +13 −13 .../oauth2/server/authorization/config/annotation/web/configurers/OAuth2TokenIntrospectionTests.java
  136. +10 −10 ...ity/oauth2/server/authorization/config/annotation/web/configurers/OAuth2TokenRevocationTests.java
  137. +29 −30 ...ty/oauth2/server/authorization/config/annotation/web/configurers/OidcClientRegistrationTests.java
  138. +6 −6 ...oauth2/server/authorization/config/annotation/web/configurers/OidcProviderConfigurationTests.java
  139. +10 −10 ...ngframework/security/oauth2/server/authorization/config/annotation/web/configurers/OidcTests.java
  140. +24 −25 ...ork/security/oauth2/server/authorization/config/annotation/web/configurers/OidcUserInfoTests.java
  141. +1 −1 .../springframework/security/oauth2/server/authorization/context/TestAuthorizationServerContext.java
  142. +2 −2 ...rver/authorization/http/converter/OAuth2AuthorizationServerMetadataHttpMessageConverterTests.java
  143. +2 −2 ...oauth2/server/authorization/http/converter/OAuth2TokenIntrospectionHttpMessageConverterTests.java
  144. +5 −5 ...va/org/springframework/security/oauth2/server/authorization/oidc/OidcClientRegistrationTests.java
  145. +8 −8 ...org/springframework/security/oauth2/server/authorization/oidc/OidcProviderConfigurationTests.java
  146. +28 −28 .../server/authorization/oidc/authentication/OidcClientConfigurationAuthenticationProviderTests.java
  147. +46 −46 ...2/server/authorization/oidc/authentication/OidcClientRegistrationAuthenticationProviderTests.java
  148. +62 −62 ...curity/oauth2/server/authorization/oidc/authentication/OidcLogoutAuthenticationProviderTests.java
  149. +15 −15 ...rity/oauth2/server/authorization/oidc/authentication/OidcUserInfoAuthenticationProviderTests.java
  150. +28 −28 ...th2/server/authorization/oidc/http/converter/OidcClientRegistrationHttpMessageConverterTests.java
  151. +2 −2 .../server/authorization/oidc/http/converter/OidcProviderConfigurationHttpMessageConverterTests.java
  152. +2 −2 ...curity/oauth2/server/authorization/oidc/http/converter/OidcUserInfoHttpMessageConverterTests.java
  153. +13 −14 ...work/security/oauth2/server/authorization/oidc/web/OidcClientRegistrationEndpointFilterTests.java
  154. +16 −17 .../springframework/security/oauth2/server/authorization/oidc/web/OidcLogoutEndpointFilterTests.java
  155. +0 −1 ...k/security/oauth2/server/authorization/oidc/web/OidcProviderConfigurationEndpointFilterTests.java
  156. +9 −10 ...pringframework/security/oauth2/server/authorization/oidc/web/OidcUserInfoEndpointFilterTests.java
  157. +1 −1 ...ringframework/security/oauth2/server/authorization/settings/AuthorizationServerSettingsTests.java
  158. +1 −1 ...t/java/org/springframework/security/oauth2/server/authorization/settings/ClientSettingsTests.java
  159. +1 −1 ...st/java/org/springframework/security/oauth2/server/authorization/settings/TokenSettingsTests.java
  160. +4 −4 ...rc/test/java/org/springframework/security/oauth2/server/authorization/test/SpringTestContext.java
  161. +2 −2 ...ringframework/security/oauth2/server/authorization/token/DelegatingOAuth2TokenGeneratorTests.java
  162. +1 −1 .../java/org/springframework/security/oauth2/server/authorization/token/JwtEncodingContextTests.java
  163. +1 −1 ...org/springframework/security/oauth2/server/authorization/token/OAuth2TokenClaimsContextTests.java
  164. +2 −2 ...ava/org/springframework/security/oauth2/server/authorization/token/OAuth2TokenClaimsSetTests.java
  165. +3 −4 ...org/springframework/security/oauth2/server/authorization/web/NimbusJwkSetEndpointFilterTests.java
  166. +50 −51 ...ingframework/security/oauth2/server/authorization/web/OAuth2AuthorizationEndpointFilterTests.java
  167. +0 −1 ...ecurity/oauth2/server/authorization/web/OAuth2AuthorizationServerMetadataEndpointFilterTests.java
  168. +17 −16 ...ringframework/security/oauth2/server/authorization/web/OAuth2ClientAuthenticationFilterTests.java
  169. +16 −17 ...mework/security/oauth2/server/authorization/web/OAuth2DeviceAuthorizationEndpointFilterTests.java
  170. +19 −20 ...amework/security/oauth2/server/authorization/web/OAuth2DeviceVerificationEndpointFilterTests.java
  171. +19 −15 .../org/springframework/security/oauth2/server/authorization/web/OAuth2TokenEndpointFilterTests.java
  172. +7 −8 ...amework/security/oauth2/server/authorization/web/OAuth2TokenIntrospectionEndpointFilterTests.java
  173. +10 −11 ...gframework/security/oauth2/server/authorization/web/OAuth2TokenRevocationEndpointFilterTests.java
  174. +3 −3 ...oauth2/server/authorization/web/authentication/ClientSecretBasicAuthenticationConverterTests.java
  175. +2 −2 .../oauth2/server/authorization/web/authentication/ClientSecretPostAuthenticationConverterTests.java
  176. +1 −1 ...auth2/server/authorization/web/authentication/JwtClientAssertionAuthenticationConverterTests.java
  177. +1 −1 .../authorization/web/authentication/OAuth2AccessTokenResponseAuthenticationSuccessHandlerTests.java
  178. +4 −3 ...uthorization/web/authentication/OAuth2DeviceAuthorizationConsentAuthenticationConverterTests.java
  179. +4 −3 ...uthorization/web/authentication/OAuth2DeviceAuthorizationRequestAuthenticationConverterTests.java
  180. +4 −3 .../oauth2/server/authorization/web/authentication/OAuth2DeviceCodeAuthenticationConverterTests.java
  181. +4 −3 ...server/authorization/web/authentication/OAuth2DeviceVerificationAuthenticationConverterTests.java
  182. +3 −3 ...rity/oauth2/server/authorization/web/authentication/PublicClientAuthenticationConverterTests.java
  183. +4 −6 ...h2/server/authorization/web/authentication/X509ClientCertificateAuthenticationConverterTests.java
2 changes: 1 addition & 1 deletion .github/workflows/release-scheduler.yml
Original file line number Diff line number Diff line change
@@ -14,7 +14,7 @@ jobs:
strategy:
matrix:
# List of active maintenance branches.
branch: [ main, 1.2.x, 1.1.x ]
branch: [ main, 1.2.x ]
runs-on: ubuntu-latest
steps:
- name: Checkout
44 changes: 0 additions & 44 deletions CODE_OF_CONDUCT.adoc

This file was deleted.

4 changes: 1 addition & 3 deletions CONTRIBUTING.adoc
Original file line number Diff line number Diff line change
@@ -4,9 +4,7 @@ Spring Authorization Server is released under the Apache 2.0 license.
If you would like to contribute something, or simply want to hack on the code this document should help you https://github.com/spring-projects/spring-authorization-server#getting-started[get started].

== Code of Conduct
This project adheres to the Contributor Covenant link:CODE_OF_CONDUCT.adoc[code of conduct].
By participating, you are expected to uphold this code.
Please report unacceptable behavior to spring-code-of-conduct@pivotal.io.
Please see our https://github.com/spring-projects/.github/blob/main/CODE_OF_CONDUCT.md[code of conduct].

== Using GitHub Issues
We use GitHub issues to track bugs and enhancements.
3 changes: 1 addition & 2 deletions README.adoc
Original file line number Diff line number Diff line change
@@ -36,8 +36,7 @@ Be sure to read the https://docs.spring.io/spring-authorization-server/reference
JavaDoc is also available for the https://docs.spring.io/spring-authorization-server/docs/current/api/[Spring Authorization Server API] and https://docs.spring.io/spring-security/site/docs/current/api/[Spring Security API].

== Code of Conduct
This project adheres to the Contributor Covenant link:CODE_OF_CONDUCT.adoc[code of conduct].
By participating, you are expected to uphold this code. Please report unacceptable behavior to spring-code-of-conduct@pivotal.io.
Please see our https://github.com/spring-projects/.github/blob/main/CODE_OF_CONDUCT.md[code of conduct].

== Downloading Artifacts
See https://github.com/spring-projects/spring-framework/wiki/Spring-Framework-Artifacts[downloading Spring artifacts] for Maven repository information.
2 changes: 1 addition & 1 deletion buildSrc/build.gradle
Original file line number Diff line number Diff line change
@@ -25,5 +25,5 @@ dependencies {
implementation "org.hidetake:gradle-ssh-plugin:2.10.1"
implementation "org.jfrog.buildinfo:build-info-extractor-gradle:5.2.0"
implementation "org.sonarsource.scanner.gradle:sonarqube-gradle-plugin:2.7.1"
implementation "org.springframework:spring-core:6.1.7"
implementation "org.springframework:spring-core:6.1.9"
}
4 changes: 2 additions & 2 deletions dependencies/spring-authorization-server-dependencies.gradle
Original file line number Diff line number Diff line change
@@ -11,7 +11,7 @@ dependencies {
api platform("org.springframework.security:spring-security-bom:$springSecurityVersion")
api platform("com.fasterxml.jackson:jackson-bom:2.17.1")
constraints {
api "com.nimbusds:nimbus-jose-jwt:9.39.1"
api "com.nimbusds:nimbus-jose-jwt:9.39.3"
api "jakarta.servlet:jakarta.servlet-api:6.0.0"
api "org.bouncycastle:bcpkix-jdk18on:1.78.1"
api "org.bouncycastle:bcprov-jdk18on:1.78.1"
@@ -21,6 +21,6 @@ dependencies {
api "com.squareup.okhttp3:mockwebserver:4.12.0"
api "com.squareup.okhttp3:okhttp:4.12.0"
api "com.jayway.jsonpath:json-path:2.9.0"
api "org.hsqldb:hsqldb:2.7.2"
api "org.hsqldb:hsqldb:2.7.3"
}
}
2 changes: 1 addition & 1 deletion docs/modules/ROOT/pages/index.adoc
Original file line number Diff line number Diff line change
@@ -13,6 +13,6 @@ xref:how-to.adoc[How-to Guides] :: Guides to get the most from Spring Authorizat

Joe Grandja, Steve Riesenberg

Copyright © 2020 - 2023
Copyright © 2020 - 2024

Copies of this document may be made for your own use and for distribution to others, provided that you do not charge any fee for such copies and further provided that each copy contains this Copyright Notice, whether distributed in print or electronically.
8 changes: 8 additions & 0 deletions etc/checkstyle/checkstyle-suppressions.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
<?xml version="1.0"?>
<!DOCTYPE suppressions PUBLIC
"-//Checkstyle//DTD SuppressionFilter Configuration 1.2//EN"
"https://checkstyle.org/dtds/suppressions_1_2.dtd">
<suppressions>
<suppress files=".*" checks="JavadocStyle" />
<suppress files="SpringAuthorizationServerVersion\.java" checks="HideUtilityClassConstructor"/>
</suppressions>
57 changes: 12 additions & 45 deletions etc/checkstyle/checkstyle.xml
Original file line number Diff line number Diff line change
@@ -1,51 +1,18 @@
<?xml version="1.0"?>
<!DOCTYPE module PUBLIC "-//Puppy Crawl//DTD Check Configuration 1.3//EN"
"https://www.puppycrawl.com/dtds/configuration_1_3.dtd">
<module name="Checker">
<!-- Suppressions -->
<!DOCTYPE module PUBLIC
"-//Checkstyle//DTD Checkstyle Configuration 1.3//EN"
"https://checkstyle.org/dtds/configuration_1_3.dtd">
<module name="com.puppycrawl.tools.checkstyle.Checker">
<module name="SuppressionFilter">
<property name="file" value="${config_loc}/suppressions.xml"/>
<property name="file"
value="${config_loc}/checkstyle-suppressions.xml" />
</module>

<!-- Root Checks -->
<module name="RegexpHeader">
<property name="headerFile" value="${config_loc}/header.txt"/>
<property name="fileExtensions" value="java"/>
<module name="com.puppycrawl.tools.checkstyle.checks.header.RegexpHeaderCheck">
<property name="headerFile" value="${config_loc}/header.txt" />
<property name="fileExtensions" value="java" />
</module>

<!-- Root Checks -->
<module name="TreeWalker">
<!-- Annotations -->
<module name="MissingOverrideCheck" />

<!-- Coding -->
<module name="EmptyStatementCheck" />
<module name="RedundantModifier" />

<!-- Imports -->
<module name="UnusedImportsCheck">
<property name="processJavadoc" value="true" />
</module>

<!-- Regexp -->
<module name="RegexpSinglelineJava">
<property name="format" value="^\t* +\t*\S"/>
<property name="message" value="Line has leading space characters; indentation should be performed with tabs only."/>
<property name="ignoreComments" value="true"/>
</module>
<module name="RegexpSinglelineJava">
<property name="maximum" value="0"/>
<property name="format" value="org\.junit\.Assert\.assert"/>
<property name="message" value="Please use AssertJ imports."/>
<property name="ignoreComments" value="true"/>
</module>
<module name="Regexp">
<property name="format" value="[ \t]+$"/>
<property name="illegalPattern" value="true"/>
<property name="message" value="Trailing whitespace"/>
</module>

<!-- Whitespace -->
<module name="WhitespaceAfterCheck" />
<module name="io.spring.javaformat.checkstyle.SpringChecks">
<property name="excludes" value="io.spring.javaformat.checkstyle.check.SpringHeaderCheck" />
<property name="excludes" value="com.puppycrawl.tools.checkstyle.checks.javadoc.JavadocPackageCheck" />
</module>
</module>
2 changes: 1 addition & 1 deletion etc/checkstyle/header.txt
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
^\Q/*\E$
^\Q * Copyright\E (\d{4}(\-\d{4})? the original author or authors\.|(\d{4}, )*(\d{4}) Acegi Technology Pty Limited)$
^\Q * Copyright \E20\d\d\-20\d\d\Q the original author or authors.\E$
^\Q *\E$
^\Q * Licensed under the Apache License, Version 2.0 (the "License");\E$
^\Q * you may not use this file except in compliance with the License.\E$
20 changes: 0 additions & 20 deletions etc/checkstyle/suppressions.xml

This file was deleted.

6 changes: 3 additions & 3 deletions gradle.properties
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
version=1.3.0
version=1.3.1
org.gradle.jvmargs=-Xmx3g -XX:+HeapDumpOnOutOfMemoryError
org.gradle.parallel=true
org.gradle.caching=true
springFrameworkVersion=6.1.7
springSecurityVersion=6.3.0
springFrameworkVersion=6.1.9
springSecurityVersion=6.3.1
springJavaformatVersion=0.0.41
checkstyleToolVersion=8.34
nohttpCheckstyleVersion=0.0.11
Original file line number Diff line number Diff line change
@@ -36,8 +36,8 @@
*
* @author Daniel Garnier-Moiroux
* @author Joe Grandja
* @see OAuth2AuthorizationServerMetadataClaimAccessor
* @since 0.1.1
* @see OAuth2AuthorizationServerMetadataClaimAccessor
* @see <a target="_blank" href="https://tools.ietf.org/html/rfc8414#section-3.2">3.2.
* Authorization Server Metadata Response</a>
* @see <a target="_blank" href=
@@ -72,8 +72,11 @@ public Map<String, Object> getClaims() {

/**
* A builder for subclasses of {@link AbstractOAuth2AuthorizationServerMetadata}.
*
* @param <T> the type of object
* @param <B> the type of the builder
*/
protected static abstract class AbstractBuilder<T extends AbstractOAuth2AuthorizationServerMetadata, B extends AbstractBuilder<T, B>> {
protected abstract static class AbstractBuilder<T extends AbstractOAuth2AuthorizationServerMetadata, B extends AbstractBuilder<T, B>> {

private final Map<String, Object> claims = new LinkedHashMap<>();

@@ -509,15 +512,15 @@ protected void validate() {
private void addClaimToClaimList(String name, String value) {
Assert.hasText(name, "name cannot be empty");
Assert.notNull(value, "value cannot be null");
getClaims().computeIfAbsent(name, k -> new LinkedList<String>());
getClaims().computeIfAbsent(name, (k) -> new LinkedList<String>());
((List<String>) getClaims().get(name)).add(value);
}

@SuppressWarnings("unchecked")
private void acceptClaimValues(String name, Consumer<List<String>> valuesConsumer) {
Assert.hasText(name, "name cannot be empty");
Assert.notNull(valuesConsumer, "valuesConsumer cannot be null");
getClaims().computeIfAbsent(name, k -> new LinkedList<String>());
getClaims().computeIfAbsent(name, (k) -> new LinkedList<String>());
List<String> values = (List<String>) getClaims().get(name);
valuesConsumer.accept(values);
}
Original file line number Diff line number Diff line change
@@ -63,7 +63,7 @@ public InMemoryOAuth2AuthorizationConsentService(OAuth2AuthorizationConsent... a
*/
public InMemoryOAuth2AuthorizationConsentService(List<OAuth2AuthorizationConsent> authorizationConsents) {
Assert.notNull(authorizationConsents, "authorizationConsents cannot be null");
authorizationConsents.forEach(authorizationConsent -> {
authorizationConsents.forEach((authorizationConsent) -> {
Assert.notNull(authorizationConsent, "authorizationConsent cannot be null");
int id = getId(authorizationConsent);
Assert.isTrue(!this.authorizationConsents.containsKey(id),
Original file line number Diff line number Diff line change
@@ -94,7 +94,7 @@ public InMemoryOAuth2AuthorizationService(OAuth2Authorization... authorizations)
*/
public InMemoryOAuth2AuthorizationService(List<OAuth2Authorization> authorizations) {
Assert.notNull(authorizations, "authorizations cannot be null");
authorizations.forEach(authorization -> {
authorizations.forEach((authorization) -> {
Assert.notNull(authorization, "authorization cannot be null");
Assert.isTrue(!this.authorizations.containsKey(authorization.getId()),
"The authorization must be unique. Found duplicate identifier: " + authorization.getId());
@@ -129,7 +129,7 @@ public void remove(OAuth2Authorization authorization) {
public OAuth2Authorization findById(String id) {
Assert.hasText(id, "id cannot be empty");
OAuth2Authorization authorization = this.authorizations.get(id);
return authorization != null ? authorization : this.initializedAuthorizations.get(id);
return (authorization != null) ? authorization : this.initializedAuthorizations.get(id);
}

@Nullable
@@ -164,19 +164,26 @@ private static boolean hasToken(OAuth2Authorization authorization, String token,
matchesRefreshToken(authorization, token) ||
matchesDeviceCode(authorization, token) ||
matchesUserCode(authorization, token);
} else if (OAuth2ParameterNames.STATE.equals(tokenType.getValue())) {
}
else if (OAuth2ParameterNames.STATE.equals(tokenType.getValue())) {
return matchesState(authorization, token);
} else if (OAuth2ParameterNames.CODE.equals(tokenType.getValue())) {
}
else if (OAuth2ParameterNames.CODE.equals(tokenType.getValue())) {
return matchesAuthorizationCode(authorization, token);
} else if (OAuth2TokenType.ACCESS_TOKEN.equals(tokenType)) {
}
else if (OAuth2TokenType.ACCESS_TOKEN.equals(tokenType)) {
return matchesAccessToken(authorization, token);
} else if (OidcParameterNames.ID_TOKEN.equals(tokenType.getValue())) {
}
else if (OidcParameterNames.ID_TOKEN.equals(tokenType.getValue())) {
return matchesIdToken(authorization, token);
} else if (OAuth2TokenType.REFRESH_TOKEN.equals(tokenType)) {
}
else if (OAuth2TokenType.REFRESH_TOKEN.equals(tokenType)) {
return matchesRefreshToken(authorization, token);
} else if (OAuth2ParameterNames.DEVICE_CODE.equals(tokenType.getValue())) {
}
else if (OAuth2ParameterNames.DEVICE_CODE.equals(tokenType.getValue())) {
return matchesDeviceCode(authorization, token);
} else if (OAuth2ParameterNames.USER_CODE.equals(tokenType.getValue())) {
}
else if (OAuth2ParameterNames.USER_CODE.equals(tokenType.getValue())) {
return matchesUserCode(authorization, token);
}
// @formatter:on
Original file line number Diff line number Diff line change
@@ -71,17 +71,6 @@
@ImportRuntimeHints(JdbcOAuth2AuthorizationConsentService.JdbcOAuth2AuthorizationConsentServiceRuntimeHintsRegistrar.class)
public class JdbcOAuth2AuthorizationConsentService implements OAuth2AuthorizationConsentService {

static class JdbcOAuth2AuthorizationConsentServiceRuntimeHintsRegistrar implements RuntimeHintsRegistrar {

@Override
public void registerHints(RuntimeHints hints, ClassLoader classLoader) {
hints.resources()
.registerResource(new ClassPathResource(
"org/springframework/security/oauth2/server/authorization/oauth2-authorization-consent-schema.sql"));
}

}

// @formatter:off
private static final String COLUMN_NAMES = "registered_client_id, "
+ "principal_name, "
@@ -288,4 +277,15 @@ public List<SqlParameterValue> apply(OAuth2AuthorizationConsent authorizationCon

}

static class JdbcOAuth2AuthorizationConsentServiceRuntimeHintsRegistrar implements RuntimeHintsRegistrar {

@Override
public void registerHints(RuntimeHints hints, ClassLoader classLoader) {
hints.resources()
.registerResource(new ClassPathResource(
"org/springframework/security/oauth2/server/authorization/oauth2-authorization-consent-schema.sql"));
}

}

}
Loading