summaryrefslogtreecommitdiffstats
path: root/Http/Firewall
Commit message (Expand)AuthorAgeFilesLines
* use authenticated token for json authenticationFabien Bourigault2017-01-021-2/+2
* [Security] Add a JSON authentication listenerKévin Dunglas2016-12-031-0/+154
* Merge branch '3.1' into 3.2Fabien Potencier2016-11-231-1/+1
|\
| * Merge branch '2.8' into 3.1Fabien Potencier2016-11-231-1/+1
| |\
| | * Merge branch '2.7' into 2.8Fabien Potencier2016-11-231-1/+1
| | |\
| | | * [HttpKernel] Revert BC breaking change of Request::isMethodSafe()Nicolas Grekas2016-11-231-1/+1
* | | | AccessDeniedException: rename object to subjectChristian Flothmann2016-09-191-1/+1
* | | | Merge branch '3.1'Nicolas Grekas2016-08-261-1/+1
|\ \ \ \ | |/ / /
| * | | Merge branch '2.8' into 3.1v3.1.4Nicolas Grekas2016-08-261-1/+1
| |\ \ \ | | |/ /
| | * | Merge branch '2.7' into 2.8v2.8.10Nicolas Grekas2016-08-261-1/+1
| | |\ \ | | | |/
| | | * SecurityBundle:BasicAuthenticationListener: removed a default argument on get...Dawid Nowak2016-08-011-1/+1
| | * | [Security] Fix deprecated usage of DigestAuthenticationEntryPoint::getKey() i...Maxime STEINHAUSSER2016-07-081-1/+1
* | | | [Security] Expose the required roles in AccessDeniedExceptionTristan Darricau2016-07-292-2/+9
|/ / /
* | | Merge branch '3.0'v3.1.0-BETA1Nicolas Grekas2016-05-122-0/+10
|\ \ \
| * \ \ Merge branch '2.8' into 3.0Fabien Potencier2016-05-092-0/+10
| |\ \ \ | | |/ /
| | * | Merge branch '2.7' into 2.8Fabien Potencier2016-05-092-0/+10
| | |\ \ | | | |/
| | | * Merge branch '2.3' into 2.7v2.7.13Fabien Potencier2016-05-092-0/+10
| | | |\
| | | | * limited the maximum length of a submitted usernamev2.3.42v2.3.41origin/2.3Fabien Potencier2016-05-091-0/+5
* | | | | Updating the error message of an AuthenticationEntryPointInterface returns a ...Ryan Weaver2016-04-271-1/+9
* | | | | Merge branch '3.0'Christian Flothmann2016-04-121-1/+2
|\ \ \ \ \ | |/ / / /
| * | | | Merge branch '2.8' into 3.0v3.0.5Christian Flothmann2016-04-121-1/+2
| |\ \ \ \ | | |/ / /
| | * | | Merge branch '2.7' into 2.8Fabien Potencier2016-04-051-1/+2
| | |\ \ \ | | | |/ /
| | | * | Merge branch '2.3' into 2.7Fabien Potencier2016-04-051-1/+2
| | | |\ \ | | | | |/
| | | | * [Security] Fixed SwitchUserListener when exiting an impersonication with Anon...Grégoire Pineau2016-04-041-1/+2
* | | | | use class constants instead of FQCN stringsChristian Flothmann2016-03-231-1/+3
* | | | | [Security] Use auth trust resolver to determine anonymous in ContextListenerWouterJ2016-03-231-3/+6
* | | | | Adding new TargetPathTrait to get/set the authentication "target_path"Ryan Weaver2016-03-021-1/+4
|/ / / /
* | | | Merge branch '2.8' into 3.0Fabien Potencier2016-01-121-4/+2
|\ \ \ \ | |/ / /
| * | | Merge branch '2.7' into 2.8Fabien Potencier2016-01-121-4/+2
| |\ \ \ | | |/ /
| | * | Merge branch '2.3' into 2.7Fabien Potencier2016-01-121-4/+2
| | |\ \ | | | |/
| | | * [2.3] Static Code Analysis for ComponentsVladimir Reznichenko2016-01-121-4/+2
| * | | [Security][SecurityBundle] Use csrf_token_id instead of deprecated intentionJakub Zalas2015-11-283-6/+36
* | | | feature #16692 [Form] Drop remaing CsrfProviderAdapter/Interface mentions (ni...Fabien Potencier2015-11-283-37/+9
|\ \ \ \
| * | | | [Form] Drop remaing CsrfProviderAdapter/Interface mentionsNicolas Grekas2015-11-283-37/+9
* | | | | [Security] remove deprecated HTTP digest auth keyChristian Flothmann2015-11-281-1/+1
|/ / / /
* | | | Merge branch '2.8'Fabien Potencier2015-11-232-3/+4
|\ \ \ \ | |/ / /
| * | | removed usage of the deprecated StringUtils::equals() methodFabien Potencier2015-11-231-2/+1
| * | | Merge branch '2.7' into 2.8Fabien Potencier2015-11-232-3/+5
| |\ \ \ | | |/ /
| | * | Merge branch '2.3' into 2.7v2.7.7Fabien Potencier2015-11-232-3/+5
| | |\ \ | | | |/
| | | * security #16631 n/a (xabbuh)v2.3.35Fabien Potencier2015-11-231-0/+8
| | | |\
| | | | * migrate session after remember me authenticationChristian Flothmann2015-11-231-0/+8
| | | * | prevent timing attacks in digest auth listenerChristian Flothmann2015-11-231-1/+2
| | | |/
* | | | Merge branch '2.8'v3.0.0-BETA1Fabien Potencier2015-11-101-4/+4
|\ \ \ \ | |/ / /
| * | | Renamed key to secretv2.8.0-BETA1WouterJ2015-11-071-4/+4
* | | | Merge branch '2.8'Fabien Potencier2015-10-181-7/+14
|\ \ \ \ | |/ / /
| * | | Merge branch '2.7' into 2.8Fabien Potencier2015-10-171-7/+14
| |\ \ \ | | |/ /
| | * | [Security] Use SessionAuthenticationStrategy on RememberMe loginSergey Novikov2015-10-161-7/+14
* | | | Merge branch '2.8'Fabien Potencier2015-09-303-11/+14
|\ \ \ \ | |/ / /
| * | | deprecate finding deep items in request parametersChristian Flothmann2015-09-303-11/+14
| |/ /
* | | [Security] Remove deprecated interfacesNicolas Grekas2015-09-032-2/+2
|/ /
* | fixes CSFabien Potencier2015-08-241-1/+1
* | Merge branch '2.3' into 2.7v2.7.3Nicolas Grekas2015-07-281-2/+6
|\ \ | |/
| * [Security] Do not save the target path in the session for a stateless firewallGrégoire Pineau2015-07-261-2/+6
* | Merge branch '2.6' into 2.7Fabien Potencier2015-07-261-2/+2
|\ \
| * \ Merge branch '2.3' into 2.6v2.6.11Fabien Potencier2015-07-261-2/+2
| |\ \ | | |/
| | * [Security] removed useless else condition in SwitchUserListener class.Hugo Hamon2015-07-221-2/+2
* | | Merge branch '2.6' into 2.7Nicolas Grekas2015-07-011-1/+2
|\ \ \ | |/ /
| * | Merge branch '2.3' into 2.6Nicolas Grekas2015-06-301-1/+2
| |\ \ | | |/
| | * [Security] Initialize SwitchUserEvent::targetUser on attemptExitUserRichard van Laak2015-06-281-1/+2
| * | Merge branch '2.3' into 2.6Fabien Potencier2015-06-281-1/+1
| |\ \ | | |/
| | * Fix quoting style consistency.ogizanagi2015-06-281-1/+1
| * | Fix mergeNicolas Grekas2015-06-181-1/+1
* | | Fix mergeNicolas Grekas2015-06-181-1/+1
* | | Merge branch '2.6' into 2.7Nicolas Grekas2015-06-185-13/+13
|\ \ \ | |/ /
| * | Merge branch '2.3' into 2.6Nicolas Grekas2015-06-185-13/+13
| |\ \ | | |/
| | * Standardize the name of the exception variablesJavier Eguiluz2015-06-155-13/+13
* | | Added a small Upgrade note regarding security.contextIltar van der Berg2015-06-151-5/+1
* | | Change error message to reflect SecurityContext deprecation.Nicholas Byfleet2015-06-051-1/+1
* | | Merge branch '2.6' into 2.7v2.7.0Fabien Potencier2015-05-221-1/+1
|\ \ \ | |/ /
| * | Merge branch '2.3' into 2.6v2.6.9v2.6.8Fabien Potencier2015-05-221-1/+1
| |\ \ | | |/
| | * Avoid redirection to XHR URIsAlessandro Siragusa2015-05-201-1/+1
* | | Merge branch '2.6' into 2.7Nicolas Grekas2015-04-181-1/+1
|\ \ \ | |/ /
| * | Merge branch '2.3' into 2.6Nicolas Grekas2015-04-181-1/+1
| |\ \ | | |/
| | * CS fixesDariusz Ruminski2015-04-161-1/+1
| * | Merge branch '2.3' into 2.6Fabien Potencier2015-03-221-1/+1
| |\ \ | | |/
| | * CS: Convert double quotes to single quotesDariusz Ruminski2015-03-211-1/+1
* | | Merge branch '2.6' into 2.7Fabien Potencier2015-02-111-0/+3
|\ \ \ | |/ /
| * | Merge branch '2.3' into 2.6Fabien Potencier2015-02-111-0/+3
| |\ \ | | |/
| | * bug #13466 [Security] Remove ContextListener's onKernelResponse listener as i...Fabien Potencier2015-02-051-0/+3
| | |\
| | | * [Security] Remove ContextListener's onKernelResponse listener as it is usedDave Marshall2015-02-051-0/+3
* | | | Merge branch '2.6' into 2.7Fabien Potencier2015-01-252-3/+3
|\ \ \ \ | |/ / /
| * | | Merge branch '2.5' into 2.6v2.6.4Fabien Potencier2015-01-252-3/+3
| |\ \ \
| | * \ \ Merge branch '2.3' into 2.5v2.5.12v2.5.11v2.5.10origin/2.5Fabien Potencier2015-01-252-3/+3
| | |\ \ \ | | | |/ /
| | | * | Removed dead code and various cleaningv2.3.25sarah khalil2015-01-212-3/+3
| | | |/
* | | | [DX] Attempt to improve logging messages with parametersIltar van der Berg2015-01-1611-49/+51
* | | | added type-hintFabien Potencier2015-01-0816-138/+57
* | | | [Security] removed usage of the deprecated SecurityContextInterfaceFabien Potencier2015-01-0816-127/+203
* | | | Merge branch '2.6' into 2.7Fabien Potencier2014-12-227-7/+8
|\ \ \ \ | |/ / /
| * | | Merge branch '2.5' into 2.6Fabien Potencier2014-12-227-7/+8
| |\ \ \ | | |/ /
| | * | Merge branch '2.3' into 2.5Fabien Potencier2014-12-227-7/+8
| | |\ \ | | | |/
| | | * [2.3] CS And DocBlock FixesGraham Campbell2014-12-227-7/+8
* | | | [Security] Added the triggering of the security.interactive_login event after...sarah khalil2014-12-161-6/+17
|/ / /
* | | Merge branch '2.5' into 2.6Fabien Potencier2014-12-051-5/+5
|\ \ \ | |/ /
| * | CS fixesGraham Campbell2014-12-041-5/+5
* | | Merge branch '2.5' into 2.6v2.6.1Fabien Potencier2014-12-021-1/+1
|\ \ \ | |/ /
| * | Merge branch '2.3' into 2.5v2.5.8Fabien Potencier2014-12-021-1/+1
| |\ \ | | |/
| | * Docblock fixesGraham Campbell2014-11-301-1/+1
* | | Merge branch '2.5'v2.6.0-BETA1Fabien Potencier2014-11-031-3/+3
|\ \ \ | |/ /
| * | Remove aligned '=>' and '='Disquedur2014-10-301-3/+3
* | | Merge branch '2.5'Fabien Potencier2014-10-264-16/+16
|\ \ \ | |/ /