|
3 | 3 |
|
4 | 4 | Spring Security 6.1 provides a number of new features.
|
5 | 5 | Below are the highlights of the release.
|
| 6 | + |
| 7 | +== Core |
| 8 | + |
| 9 | +* https://github.com/spring-projects/spring-security/issues/12233[gh-12233] - SecuredAuthorizationManager allows customizing underlying AuthorizationManager |
| 10 | +* https://github.com/spring-projects/spring-security/issues/12231[gh-12231] - Add Authority Collection Authorization Manager |
| 11 | + |
| 12 | +== OAuth 2.0 |
| 13 | + |
| 14 | +* https://github.com/spring-projects/spring-security/issues/10309[gh-10309] - xref:servlet/oauth2/resource-server/jwt.adoc[(docs)] - Add Nimbus(Reactive)JwtDecoder#withIssuerLocation |
| 15 | +* https://github.com/spring-projects/spring-security/issues/12907[gh-12907] - Configure principal claim name in ReactiveJwtAuthenticationConverter |
| 16 | + |
| 17 | +== SAML 2.0 |
| 18 | + |
| 19 | +* https://github.com/spring-projects/spring-security/issues/12604[gh-12604] - Support AuthnRequestSigned metadata attribute |
| 20 | +* https://github.com/spring-projects/spring-security/issues/12846[gh-12846] - Metadata supports multiple entities and EntitiesDescriptor |
| 21 | +* https://github.com/spring-projects/spring-security/issues/11828[gh-11828] - xref:servlet/saml2/metadata.adoc[(docs)] - Add saml2Metadata to DSL |
| 22 | +* https://github.com/spring-projects/spring-security/issues/12843[gh-12843] - xref:servlet/saml2/logout.adoc[(docs)] - Allow Relying Party to be Deduced from LogoutRequest |
| 23 | +* https://github.com/spring-projects/spring-security/issues/10243[gh-10243] - xref:servlet/saml2/login/authentication.adoc[(docs)] - Allow Relying Party to be Deduced from SAML Response |
| 24 | +* https://github.com/spring-projects/spring-security/issues/12842[gh-12842] - Add RelyingPartyRegistration placeholder resolution component |
| 25 | +* https://github.com/spring-projects/spring-security/issues/12845[gh-12845] - Support issuing LogoutResponse after already logged out |
| 26 | + |
| 27 | +== Observability |
| 28 | + |
| 29 | +* https://github.com/spring-projects/spring-security/issues/12534[gh-12534] - Customize Authentication and Authorization observation conventions |
| 30 | + |
| 31 | +== Web |
| 32 | + |
| 33 | +* https://github.com/spring-projects/spring-security/issues/12751[gh-12751] - Add RequestMatchers factory class |
| 34 | +* https://github.com/spring-projects/spring-security/issues/12847[gh-12847] - Propagate variables through And and OrRequestMatcher |
| 35 | + |
| 36 | +== Docs |
| 37 | + |
| 38 | +In our ongoing efforts to update Spring Security's documentation, several additional sections were fully re-written: |
| 39 | + |
| 40 | +* https://github.com/spring-projects/spring-security/issues/13088[gh-13088] - xref:servlet/authorization/index.adoc[(docs)] - Revisit Authorization documentation |
| 41 | +* https://github.com/spring-projects/spring-security/issues/12681[gh-12681] - xref:servlet/authentication/session-management.adoc[(docs)] - Revisit Session Management documentation |
| 42 | +* https://github.com/spring-projects/spring-security/issues/13062[gh-13062] - xref:servlet/authentication/logout.adoc[(docs)] - Revisit Logout documentation |
0 commit comments