[jira] [Commented] (SHIRO-216) Add @Documented to Shiro authorization annotations

2021-08-23 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-216?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17403327#comment-17403327 ] Brian Demers commented on SHIRO-216: PR [merged]: https://github.com/apache/shiro/pull/318 > Add

[jira] [Commented] (SHIRO-206) Support for JSF/Facelets

2021-08-18 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-206?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17401276#comment-17401276 ] Brian Demers commented on SHIRO-206: IIRC, it was pulled out of main because it didn't have tests (or

[jira] [Commented] (SHIRO-826) HTTP 400 with encoded umlauts in URL

2021-07-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-826?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17383639#comment-17383639 ] Brian Demers commented on SHIRO-826: Hey [~sgessner]!   I just had a chance to dig into this a bit

[jira] [Commented] (SHIRO-826) HTTP 400 with encoded umlauts in URL

2021-07-16 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-826?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17382097#comment-17382097 ] Brian Demers commented on SHIRO-826: Thanks [~sgessner]!  Any chance you have anything in your logs?

[jira] [Commented] (SHIRO-825) Trailing slash in URI results in "IllegalArgumentException: There is no configured chain under the name/key"

2021-07-06 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-825?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17375994#comment-17375994 ] Brian Demers commented on SHIRO-825: [~zalbee], nm I found the test gap... I was looking in the wrong

[jira] [Commented] (SHIRO-815) Null Pointer Exception during Shiro cleanup

2021-06-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-815?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17360116#comment-17360116 ] Brian Demers commented on SHIRO-815: @Surya, we strongly encourage you to upgrade regardless if it

[jira] [Commented] (SHIRO-824) how to create an allow list avoid deserialize vulnerability

2021-06-07 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-824?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17358749#comment-17358749 ] Brian Demers commented on SHIRO-824: Hey [~k4n5hao]! The mailing lists are a better place to ask

[jira] [Closed] (SHIRO-824) how to create an allow list avoid deserialize vulnerability

2021-06-07 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-824?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers closed SHIRO-824. -- Resolution: Not A Problem > how to create an allow list avoid deserialize vulnerability >

[jira] [Commented] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17352212#comment-17352212 ] Brian Demers commented on SHIRO-821: Oh, you are suggesting that there is just a missing ‘trim()’

[jira] [Commented] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17352094#comment-17352094 ] Brian Demers commented on SHIRO-821: [~nidhikv], I'm not sure I understand. Your patterns end with a

[jira] [Comment Edited] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17352049#comment-17352049 ] Brian Demers edited comment on SHIRO-821 at 5/26/21, 9:11 PM: -- That looks

[jira] [Commented] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17352049#comment-17352049 ] Brian Demers commented on SHIRO-821: That looks like a bug to me that has now been corrected. 

[jira] [Commented] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17351875#comment-17351875 ] Brian Demers commented on SHIRO-821: [~nidhikv] I've tried to quickly reproduce this issue.  Is that

[jira] [Updated] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-821: --- Description: Hi,     Not sure if this is a bug but there appears to be a difference in the way

[jira] [Updated] (SHIRO-821) Difference in behaviour when matching regex patterns with trailing spaces between shiro-core v1.7.0 and v1.7.1

2021-05-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-821?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-821: --- Description: Hi,     Not sure if this is a bug but there appears to be a difference in the way

[jira] [Created] (SHIRO-813) Create private git repo `shiro-private`

2021-04-13 Thread Brian Demers (Jira)
Brian Demers created SHIRO-813: -- Summary: Create private git repo `shiro-private` Key: SHIRO-813 URL: https://issues.apache.org/jira/browse/SHIRO-813 Project: Shiro Issue Type: New Git Repo

[jira] [Assigned] (SHIRO-730) Updates the default Cipher mode to GCM in AesCipherService

2021-04-13 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-730?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers reassigned SHIRO-730: -- Assignee: (was: Brian Demers) > Updates the default Cipher mode to GCM in AesCipherService

[jira] [Assigned] (SHIRO-730) Updates the default Cipher mode to GCM in AesCipherService

2021-04-13 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-730?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers reassigned SHIRO-730: -- Assignee: Brian Demers > Updates the default Cipher mode to GCM in AesCipherService >

[jira] [Resolved] (SHIRO-808) security enhance

2021-02-16 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-808?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-808. Resolution: Incomplete > security enhance > > > Key: SHIRO-808 >

[jira] [Commented] (SHIRO-808) security enhance

2021-02-16 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-808?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17285301#comment-17285301 ] Brian Demers commented on SHIRO-808: Blocklists are not an effective mechanism for this type of

[jira] [Commented] (SHIRO-803) Migrate to Jakarta APIs

2020-12-16 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-803?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17250602#comment-17250602 ] Brian Demers commented on SHIRO-803: Nothing set, but if you are interested, start a thread on the dev

[jira] [Closed] (SHIRO-803) Migrate to Jakarta APIs

2020-12-15 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-803?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers closed SHIRO-803. -- Fix Version/s: (was: 2.0.0) Resolution: Duplicate It's on the roadmap! > Migrate to Jakarta

[jira] [Comment Edited] (SHIRO-801) Shiro blocks requests with non-ACII characters in the URL path

2020-11-20 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-801?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17236254#comment-17236254 ] Brian Demers edited comment on SHIRO-801 at 11/20/20, 3:55 PM: --- There are a

[jira] [Commented] (SHIRO-801) Shiro blocks requests with non-ACII characters in the URL path

2020-11-20 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-801?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17236254#comment-17236254 ] Brian Demers commented on SHIRO-801: There are a few unicode based attacks,

[jira] [Commented] (SHIRO-800) shiro-core tests jar not in maven central for 1.7.0

2020-11-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-800?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17235721#comment-17235721 ] Brian Demers commented on SHIRO-800: Hey Tim!   I don't think it was intentionally removed, but in

[jira] [Commented] (SHIRO-799) When ThreadContext works with ThreadPool bring security issues

2020-11-13 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-799?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17231610#comment-17231610 ] Brian Demers commented on SHIRO-799: Hi [~Leven] If you think there is a security concern in a

[jira] [Commented] (SHIRO-798) Improvement in Shiro API

2020-11-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-798?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17228815#comment-17228815 ] Brian Demers commented on SHIRO-798: Thank you, that is very helpful > Improvement in Shiro API >

[jira] [Commented] (SHIRO-798) Improvement in Shiro API

2020-11-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-798?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17228809#comment-17228809 ] Brian Demers commented on SHIRO-798: I understand, the JPMS concern, see SHIRO-781.   I'm asking

[jira] [Commented] (SHIRO-798) Improvement in Shiro API

2020-11-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-798?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17228780#comment-17228780 ] Brian Demers commented on SHIRO-798: I’ve been following them, and I asked a similar question there

[jira] [Commented] (SHIRO-798) Improvement in Shiro API

2020-11-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-798?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17228649#comment-17228649 ] Brian Demers commented on SHIRO-798: Thanks for creating the issue [~Pavel_K]!   Taking a step back,

[jira] [Commented] (SHIRO-796) Move away from ThreadLocals

2020-11-05 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-796?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17226936#comment-17226936 ] Brian Demers commented on SHIRO-796: Shiro-Web does bind the Subject current thread (which would be a

[jira] [Commented] (SHIRO-796) Move away from ThreadLocals

2020-11-04 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-796?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17226249#comment-17226249 ] Brian Demers commented on SHIRO-796: [~boris-petrov] Do you have a suggstion as a replacement?  Those

[jira] [Commented] (SHIRO-797) Shiro 1.7.0 is lower than using springboot version 2.0.7 dependency error

2020-11-04 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-797?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17226239#comment-17226239 ] Brian Demers commented on SHIRO-797: [~BG317957] can you submit a PR?

[jira] [Commented] (SHIRO-795) Disable session path rewriting by default

2020-10-24 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-795?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17220122#comment-17220122 ] Brian Demers commented on SHIRO-795: IMHO, the "to be even more secure" part is not correct, rewriting

[jira] [Commented] (SHIRO-795) Disable session path rewriting by default

2020-10-24 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-795?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17220097#comment-17220097 ] Brian Demers commented on SHIRO-795: Sorry about that, I thought it would get linked automatically: 

[jira] [Resolved] (SHIRO-789) Also add cookie SameSite option to Spring

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-789?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-789. Resolution: Fixed > Also add cookie SameSite option to Spring >

[jira] [Updated] (SHIRO-740) SslFilter with HTTP Strict Transport Security (HSTS)

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-740?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-740: --- Fix Version/s: (was: 1.6.1) > SslFilter with HTTP Strict Transport Security (HSTS) >

[jira] [Updated] (SHIRO-792) ShiroWebFilterConfiguration seems to conflict with other FilterRegistrationBean

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-792?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-792: --- Fix Version/s: (was: 1.6.1) 1.7.0 > ShiroWebFilterConfiguration seems to

[jira] [Resolved] (SHIRO-792) ShiroWebFilterConfiguration seems to conflict with other FilterRegistrationBean

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-792?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-792. Resolution: Fixed > ShiroWebFilterConfiguration seems to conflict with other >

[jira] [Reopened] (SHIRO-792) ShiroWebFilterConfiguration seems to conflict with other FilterRegistrationBean

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-792?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers reopened SHIRO-792: > ShiroWebFilterConfiguration seems to conflict with other > FilterRegistrationBean >

[jira] [Updated] (SHIRO-789) Also add cookie SameSite option to Spring

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-789?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-789: --- Fix Version/s: (was: 1.6.1) 1.7.0 > Also add cookie SameSite option to Spring

[jira] [Updated] (SHIRO-767) org.apache.shiro.util.ClassUtil cannot load the array of Primitive DataType when use undertown as web container

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-767?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-767: --- Fix Version/s: (was: 1.6.1) 1.7.0 > org.apache.shiro.util.ClassUtil cannot

[jira] [Resolved] (SHIRO-795) Disable session path rewriting by default

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-795?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-795. Fix Version/s: 1.7.0 2.0.0 Resolution: Fixed > Disable session path

[jira] [Resolved] (SHIRO-794) Add system property to enable backslash path normalization

2020-10-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-794?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-794. Fix Version/s: 1.7.0 Resolution: Fixed > Add system property to enable backslash path

[jira] [Created] (SHIRO-795) Disable session path rewriting by default

2020-10-19 Thread Brian Demers (Jira)
Brian Demers created SHIRO-795: -- Summary: Disable session path rewriting by default Key: SHIRO-795 URL: https://issues.apache.org/jira/browse/SHIRO-795 Project: Shiro Issue Type: Improvement

[jira] [Created] (SHIRO-794) Add system property to enable backslash path normalization

2020-10-19 Thread Brian Demers (Jira)
Brian Demers created SHIRO-794: -- Summary: Add system property to enable backslash path normalization Key: SHIRO-794 URL: https://issues.apache.org/jira/browse/SHIRO-794 Project: Shiro Issue

[jira] [Resolved] (SHIRO-793) deleteMe cookie should use the defined "sameSite"

2020-10-17 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-793?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-793. Resolution: Resolved > deleteMe cookie should use the defined "sameSite" >

[jira] [Created] (SHIRO-793) deleteMe cookie should use the defined "sameSite"

2020-10-17 Thread Brian Demers (Jira)
Brian Demers created SHIRO-793: -- Summary: deleteMe cookie should use the defined "sameSite" Key: SHIRO-793 URL: https://issues.apache.org/jira/browse/SHIRO-793 Project: Shiro Issue Type: Task

[jira] [Commented] (SHIRO-783) AES 256 encryption yeilds unsupported Tlen error on all shiro versions above 1.4.1

2020-10-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-783?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17211314#comment-17211314 ] Brian Demers commented on SHIRO-783: Thanks for following up with this! > AES 256 encryption yeilds

[jira] [Commented] (SHIRO-792) ShiroWebFilterConfiguration seems to conflict with other FilterRegistrationBean

2020-08-26 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-792?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17185317#comment-17185317 ] Brian Demers commented on SHIRO-792: For 1.6 adding a name seems like the most compatible option.  

[jira] [Commented] (SHIRO-783) AES 256 encryption yeilds unsupported Tlen error on all shiro versions above 1.4.1

2020-08-24 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-783?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17183419#comment-17183419 ] Brian Demers commented on SHIRO-783: It should be something like (from memory, forgive any typos):

[jira] [Updated] (SHIRO-791) Update Shiro Javadoc deployment to new Git URL

2020-08-22 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-791?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-791: --- Description: The Javadoc building is still configured to publish to SVN,  we need to update the

[jira] [Created] (SHIRO-791) Update Shiro Javadoc deployment to new Git URL

2020-08-22 Thread Brian Demers (Jira)
Brian Demers created SHIRO-791: -- Summary: Update Shiro Javadoc deployment to new Git URL Key: SHIRO-791 URL: https://issues.apache.org/jira/browse/SHIRO-791 Project: Shiro Issue Type: Task

[jira] [Closed] (SHIRO-787) Expose shiro.sessionManager.cookie.sameSite in Spring config

2020-08-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-787?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers closed SHIRO-787. -- Resolution: Duplicate > Expose shiro.sessionManager.cookie.sameSite in Spring config >

[jira] [Commented] (SHIRO-790) sessionIdUrlRewritingEnabled and InvalidRequestFilter conflict

2020-08-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-790?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17180631#comment-17180631 ] Brian Demers commented on SHIRO-790: This is a known issue, please see the following section in the

[jira] [Resolved] (SHIRO-788) Add support for Global Filters

2020-08-11 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-788?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-788. Resolution: Fixed > Add support for Global Filters > -- > >

[jira] [Updated] (SHIRO-740) SslFilter with HTTP Strict Transport Security (HSTS)

2020-08-11 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-740?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-740: --- Fix Version/s: (was: 1.6.0) 1.6.1 > SslFilter with HTTP Strict Transport

[jira] [Commented] (SHIRO-783) AES 256 encryption yeilds unsupported Tlen error on all shiro versions above 1.4.1

2020-06-30 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-783?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17148962#comment-17148962 ] Brian Demers commented on SHIRO-783: Hi [~pharder123]!   In Shiro 1.4.2 the AesCipherService's

[jira] [Comment Edited] (SHIRO-753) Regression in URI parsing in Shiro 1.5.2

2020-06-24 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-753?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17143916#comment-17143916 ] Brian Demers edited comment on SHIRO-753 at 6/24/20, 3:13 PM: --

[jira] [Commented] (SHIRO-753) Regression in URI parsing in Shiro 1.5.2

2020-06-24 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-753?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17143916#comment-17143916 ] Brian Demers commented on SHIRO-753: [~sourabhsparkala] The line you referenced is no longer used by

[jira] [Commented] (SHIRO-782) Bypass shiroFilter ACL

2020-06-19 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-782?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17140611#comment-17140611 ] Brian Demers commented on SHIRO-782: Thank you for keeping the details private to allow for

[jira] [Commented] (SHIRO-769) Multiple realm exceptions cannot be catch

2020-05-07 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-769?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17101722#comment-17101722 ] Brian Demers commented on SHIRO-769: Thanks [~gexiuyu]!   When it comes to supporting multiple

[jira] [Commented] (SHIRO-766) ArrayIndexOutOfBoundsException in Base64#decode

2020-05-06 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-766?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17100827#comment-17100827 ] Brian Demers commented on SHIRO-766: Thanks [~eiden]!   We have a fix, I just wanted to make sure

[jira] [Comment Edited] (SHIRO-766) ArrayIndexOutOfBoundsException in Base64#decode

2020-05-05 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-766?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17099945#comment-17099945 ] Brian Demers edited comment on SHIRO-766 at 5/5/20, 2:23 PM: - Hi [~eiden]!

[jira] [Created] (SHIRO-763) Make Shiro's ThreadLocal Storage configurable

2020-04-30 Thread Brian Demers (Jira)
Brian Demers created SHIRO-763: -- Summary: Make Shiro's ThreadLocal Storage configurable Key: SHIRO-763 URL: https://issues.apache.org/jira/browse/SHIRO-763 Project: Shiro Issue Type:

[jira] [Commented] (SHIRO-760) Bypass shiroFilter ACL

2020-04-23 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-760?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090806#comment-17090806 ] Brian Demers commented on SHIRO-760: [~cl0und] Please report security-related issues or questions

[jira] [Commented] (SHIRO-743) Spring bean post processing mishap

2020-04-23 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-743?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090657#comment-17090657 ] Brian Demers commented on SHIRO-743: [~chrispoulsen] Can you put together a simple example app to

[jira] [Commented] (SHIRO-588) DefaultLdapRealm should extend AbstractLdapRealm

2020-04-10 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-588?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17080508#comment-17080508 ] Brian Demers commented on SHIRO-588: +1 for cleaning up the structure in 2.0 LDAP is tricky, it been

[jira] [Commented] (SHIRO-753) Regression in URI parsing in Shiro 1.5.2

2020-04-07 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-753?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17077530#comment-17077530 ] Brian Demers commented on SHIRO-753: https://github.com/apache/shiro/pull/211 > Regression in URI

[jira] [Commented] (SHIRO-753) Regression in URI parsing in Shiro 1.5.2

2020-04-07 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-753?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17077401#comment-17077401 ] Brian Demers commented on SHIRO-753: Looking in to it > Regression in URI parsing in Shiro 1.5.2 >

[jira] [Commented] (SHIRO-730) Updates the default Cipher mode to GCM in AesCipherService

2020-04-02 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-730?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17073934#comment-17073934 ] Brian Demers commented on SHIRO-730: [~rivanov] It depends on how you are configuring Shiro. If you

[jira] [Resolved] (SHIRO-510) java.lang.StackOverflowError in shiro

2020-03-30 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-510?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-510. Resolution: Cannot Reproduce Thanks for checking on this [~bmarwell]! >

[jira] [Commented] (SHIRO-751) SimplePrincipalMap and SimplePrincipalCollection throw different exceptions for the same problem

2020-03-27 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-751?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17069190#comment-17069190 ] Brian Demers commented on SHIRO-751: Thanks [~haozhong]! Any chance you want to send a us a PR? :)

[jira] [Commented] (SHIRO-750) Migrate to jakarta APIs

2020-03-27 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-750?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17068995#comment-17068995 ] Brian Demers commented on SHIRO-750: I'm sorry, I was assuming you were talking about the new Jakarta

[jira] [Commented] (SHIRO-750) Migrate to jakarta APIs

2020-03-27 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-750?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17068719#comment-17068719 ] Brian Demers commented on SHIRO-750: This would be a breaking change. So it would need to wait for a

[jira] [Created] (SHIRO-749) shiro-all jar is missing cache package

2020-03-16 Thread Brian Demers (Jira)
Brian Demers created SHIRO-749: -- Summary: shiro-all jar is missing cache package Key: SHIRO-749 URL: https://issues.apache.org/jira/browse/SHIRO-749 Project: Shiro Issue Type: Bug

[jira] [Commented] (SHIRO-678) Strings garbled when POST without JSESSIONID cookie

2020-03-13 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17058784#comment-17058784 ] Brian Demers commented on SHIRO-678: Cool! I'm not sure there is anything Shiro can do on this. I'm

[jira] [Comment Edited] (SHIRO-678) Strings garbled when POST without JSESSIONID cookie

2020-03-12 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17058162#comment-17058162 ] Brian Demers edited comment on SHIRO-678 at 3/12/20, 6:34 PM: -- [~bmarwell] is

[jira] [Commented] (SHIRO-678) Strings garbled when POST without JSESSIONID cookie

2020-03-12 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17058162#comment-17058162 ] Brian Demers commented on SHIRO-678: [~bmarwell] is setting the container's default character set an

[jira] [Commented] (SHIRO-678) Strings garbled when POST without JSESSIONID cookie

2020-03-12 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17058116#comment-17058116 ] Brian Demers commented on SHIRO-678: Hi [~bmarwell] I added a pull request to that repo that _fixes_

[jira] [Commented] (SHIRO-747) FirstSuccessfulStrategy doesn't properly short circuit

2020-03-11 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-747?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17057324#comment-17057324 ] Brian Demers commented on SHIRO-747: Thanks [~twbecker], That was helpful! I've created a PR for

[jira] [Commented] (SHIRO-747) FirstSuccessfulStrategy doesn't properly short circuit

2020-03-11 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-747?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17057084#comment-17057084 ] Brian Demers commented on SHIRO-747: Hi [~twbecker] ! This report doesn't contain enough information

[jira] [Resolved] (SHIRO-746) Inconsistent library versions notice.

2020-03-01 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-746?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-746. Resolution: Invalid This issue resembles a bot opening an issue.   This is expected, we have ITs

[jira] [Closed] (SHIRO-746) Inconsistent library versions notice.

2020-03-01 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-746?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers closed SHIRO-746. -- > Inconsistent library versions notice. > - > > Key:

[jira] [Commented] (SHIRO-744) Overlapping classes cause warnings when shading.

2020-02-27 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-744?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17046856#comment-17046856 ] Brian Demers commented on SHIRO-744: [~andy] I'll reopen it to make it more clear. The underlying

[jira] [Reopened] (SHIRO-744) Overlapping classes cause warnings when shading.

2020-02-27 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-744?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers reopened SHIRO-744: > Overlapping classes cause warnings when shading. > >

[jira] [Closed] (SHIRO-744) Overlapping classes cause warnings when shading.

2020-02-27 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-744?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers closed SHIRO-744. -- > Overlapping classes cause warnings when shading. > > >

[jira] [Assigned] (SHIRO-743) Spring bean post processing mishap

2020-02-25 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-743?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers reassigned SHIRO-743: -- Assignee: Brian Demers (was: Les Hazlewood) > Spring bean post processing mishap >

[jira] [Commented] (SHIRO-743) Spring bean post processing mishap

2020-02-25 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-743?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044562#comment-17044562 ] Brian Demers commented on SHIRO-743: Thanks for the report! We will take a look! > Spring bean post

[jira] [Updated] (SHIRO-627) something wrong with shiro-spring-boot-web-starter,it did not auto register securityManager???

2020-02-03 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-627?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers updated SHIRO-627: --- Fix Version/s: (was: 1.5.1) 1.6.0 > something wrong with

[jira] [Commented] (SHIRO-678) Strings garbled when POST without JSESSIONID cookie

2020-02-01 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-678?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17028112#comment-17028112 ] Brian Demers commented on SHIRO-678: I’m actually more interested in your non-Shiro example more (I

[jira] [Commented] (SHIRO-627) something wrong with shiro-spring-boot-web-starter,it did not auto register securityManager???

2020-01-30 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-627?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17027050#comment-17027050 ] Brian Demers commented on SHIRO-627: >From GitHub: > I see the issue now, but this would be a

[jira] [Resolved] (SHIRO-736) DefaultCipherInstance is an alias which is not available in every JVM or JCA Provider

2020-01-30 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-736?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers resolved SHIRO-736. Resolution: Fixed > DefaultCipherInstance is an alias which is not available in every JVM or JCA >

[jira] [Closed] (SHIRO-283) Add ability to support basic auth and form authentication simultaneously

2020-01-22 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-283?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Brian Demers closed SHIRO-283. -- Resolution: Resolved Answer/solution provided in comment above > Add ability to support basic auth and

[jira] [Commented] (SHIRO-736) DefaultCipherInstance is an alias which is not available in every JVM or JCA Provider

2020-01-16 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-736?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17017456#comment-17017456 ] Brian Demers commented on SHIRO-736: Thanks [~bmarwell]! I just found this in the Java 14 release

[jira] [Commented] (SHIRO-730) Updates the default Cipher mode to GCM in AesCipherService

2020-01-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-730?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17012270#comment-17012270 ] Brian Demers commented on SHIRO-730: No worries [~prebholz]! It's a valid point we could have made a

[jira] [Commented] (SHIRO-730) Updates the default Cipher mode to GCM in AesCipherService

2020-01-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-730?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17012212#comment-17012212 ] Brian Demers commented on SHIRO-730: Hi [~prebholz] This was fixed in SHIRO-721 for CVE-2019-12422

[jira] [Commented] (SHIRO-732) Configuration conflict

2019-12-16 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-732?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16997407#comment-16997407 ] Brian Demers commented on SHIRO-732: What do your dependencies resolve to? can you get a dependency

[jira] [Commented] (SHIRO-732) Configuration conflict

2019-12-09 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-732?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16991731#comment-16991731 ] Brian Demers commented on SHIRO-732: What do your resolved dependencies look like? > Configuration

[jira] [Commented] (SHIRO-732) Configuration conflict

2019-12-08 Thread Brian Demers (Jira)
[ https://issues.apache.org/jira/browse/SHIRO-732?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16990915#comment-16990915 ] Brian Demers commented on SHIRO-732: What dependencies are you including? Are you using Maven or

  1   2   3   4   5   >