SEC-1152: auto-config changes: Move <anonymous> to default configuration #1400

Closed
spring-issuemaster opened this Issue May 4, 2009 · 2 comments

1 participant

@spring-issuemaster

Luke Taylor (Migrated from SEC-1152) said:

An AnonymousProcessingFilter should probably be added to the configuration by default, rather than only with auto-config, with the option of disabling it by using an "enabled" flag on the element:

The AnonymousProcessingFilter has very little impact on most apps, but some users try to use the corresponding IS_AUTHENTICATED attributes without auto-config enabled and don't realise why it doesn't work.

@spring-issuemaster

Luke Taylor said:

Remember-me part was already done (SEC-1044). Changing description to apply only to anonymous auth.

@spring-issuemaster

Luke Taylor said:

I've modified HttpSecurityBeanDefinitionParser and its tests to enable the anonymous filter by default.

@spring-issuemaster spring-issuemaster added this to the 3.0.0 M1 milestone Feb 5, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment