差沙的密碼 -- SSHWSFC's code
          閱讀本Blog請(qǐng)自備塑料袋一只
          posts - 14,  comments - 59,  trackbacks - 0
          acegi1.0發(fā)布,其實(shí)有點(diǎn)出乎意料,因?yàn)槲乙幌蛘J(rèn)為acegi的代碼已經(jīng)相當(dāng)穩(wěn)定了,但是acegi力求精益求精,從新版還是能看到不少實(shí)用的改動(dòng)和升級(jí)。這里簡(jiǎn)單分析一下。

          [SEC-183] - Avoid unnecessary HttpSession creation when using Anonymous and Remember-Me authentication

          以前如果使用HttpSessionContextIntegrationFilter的話,不管你是否需要?jiǎng)?chuàng)建session,他都會(huì)給你創(chuàng)建。這在一些Base驗(yàn)證的時(shí)候是多余的。現(xiàn)在加上了forceEagerSessionCreation,在創(chuàng)建session的時(shí)候做了控制。

          [SEC-29] - Save POST request parameters before redirect

          在前幾個(gè)版本出現(xiàn)這個(gè)問(wèn)題,如果實(shí)現(xiàn)了登陸自動(dòng)跳轉(zhuǎn),acegi僅僅是簡(jiǎn)單記錄了URL,沒(méi)有深入的紀(jì)錄信息。新版本中acegi不僅僅是保持POST中的數(shù)據(jù)不會(huì)丟失,request里面的東西幾乎全都序列化保存下來(lái)了,實(shí)現(xiàn)可以看看SavedRequest。

          [SEC-40] - HibernateDao.scroll() performance

          [SEC-92] - Hibernate ACL implementation

          這個(gè)比較激動(dòng)的改進(jìn)在1.0的源碼中沒(méi)有找到,看alex的意思好像是僅僅提供各演示,目的是為了生成數(shù)據(jù)腳本方便點(diǎn)。(其實(shí)這個(gè)還真的沒(méi)法做成特別通用的,畢竟每個(gè)人的ACL實(shí)現(xiàn)都有可能不同)

          [SEC-147] - BasicAclEntryAfterInvocationProvider should support processDomainObjectClass

          對(duì)List進(jìn)行ACL交驗(yàn)的時(shí)候,會(huì)把第一個(gè)元素取出,看看是否AssignableFrom這個(gè)processDomainObjectClass ,算是做一下安全檢查吧。

          [SEC-172] - Allow SimpleAclEntry to take 'null' as recipient constructor argument

          其實(shí)應(yīng)該是不允許recipient 為空。

          [SEC-187] - inHttp & inHttps not fully utilized in AuthenticationProcessingFilterEntryPoint

          [SEC-191] - AclTag class should use the BeanFactoryUtils.beanNamesForTypeIncludingAncestors method to search for the AclManager

          AclTag在尋找AclManager 時(shí)候會(huì)更加靈活了,得益于spring的強(qiáng)大。

          <明天繼續(xù)吧。。。。>

          [SEC-194] - RememberMeServices should be available when using BasicAuth logins

          [SEC-195] - Create Acegi-backed CAS3 AuthenticationHandler

          [SEC-196] - Update web site and documentation to reference JA-SIG CAS

          [SEC-203] - Allow setting the AuthenticationManager onto the ConcurrentSessionController for inverted dependency

          [SEC-204] - Better detection of malformed text in FilterInvocationDefinitionSourceEditor

          [SEC-205] - Allow multiple URLs in DefaultInitialDirContextFactory

          [SEC-206] - TokenBasedRememberMeServices using context root when setting cookie paths (inc code)

          [SEC-207] - Implement countermeasures against session attacks

          [SEC-209] - Make AbstractProcessingFilter.eventPublisher field protected

          [SEC-217] - Improve Siteminder Filter

          [SEC-220] - Allow ExceptionTranslationFilter to not catch exceptions

          [SEC-221] - AbstractProcessingFilter.onPreAuthentication exceptions should be caught

          [SEC-224] - Make Authentication.getPrincipal() for CAS return the UserDetails

          [SEC-229] - Allow redirects to external URLs in AbstractProcessingFilter

          [SEC-231] - Add another DefaultLdapAuthoritiesPopulator.getGroupMembershipRoles

          [SEC-234] - Allow WebAuthenticationDetails pluggable implementations

          [SEC-236] - JbossAcegiLoginModule to use ApplicationContext interface

          [SEC-238] - Add AuthenticationException to AbstractProcessingFilter.onUnsuccessfulAuthentication method signature

          [SEC-242] - Logger in AbstractProcessingFilter

          [SEC-244] - Column names instead of indexes for org.acegisecurity.userdetails.jdbc.JdbcDaoImpl

          [SEC-246] - Enable late-binding of UserDetailsService on DaoAuthenticationProvider

          [SEC-247] - Allow to specify resources that shouldn't be filtered in FilterChainProxy

          [SEC-251] - DefaultLdapAuthoritiesPopulator: Add filter argument {1} for username as in Tomcat JNDIRealm

          [SEC-255] - Reorder AuthenticationProcessingFilter to create HttpSession before delegating to AuthenticationDetailsSource

          [SEC-257] - ExceptionTranslationFilter to use strategy interface for AccessDeniedException handling

          [SEC-259] - AccessDecisionVoter: typo in JavaDoc

          [SEC-260] - AbstractAccessDecisionManager and loggers

          [SEC-262] - AbstractAccessDecisionManager needs standard handling ifAllAbstainDecisions

          [SEC-264] - Introduction of LdapUserDetails and changes to LdapAuthenticator and LdapAuthoritiesPopulator interfaces

          [SEC-276] - Restructure reference guide

          posted on 2006-06-01 23:05 差沙 閱讀(560) 評(píng)論(0)  編輯  收藏

          只有注冊(cè)用戶登錄后才能發(fā)表評(píng)論。


          網(wǎng)站導(dǎo)航:
           
          這家伙很懶,但起碼還是寫(xiě)了一句話。

          <2006年6月>
          28293031123
          45678910
          11121314151617
          18192021222324
          2526272829301
          2345678

          常用鏈接

          留言簿(8)

          隨筆分類

          隨筆檔案

          文章分類

          搜索

          •  

          最新評(píng)論

          閱讀排行榜

          評(píng)論排行榜

          主站蜘蛛池模板: 水富县| 平度市| 哈密市| 博野县| 门头沟区| 儋州市| 广西| 稷山县| 达孜县| 芦山县| 湖南省| 广元市| 通许县| 永康市| 蛟河市| 大厂| 文昌市| 商都县| 普兰县| 沙洋县| 宜丰县| 介休市| 林州市| 湟源县| 绥滨县| 东乡族自治县| 常州市| 建水县| 石楼县| 牡丹江市| 双桥区| 巩留县| 香河县| 自治县| 时尚| 嘉黎县| 兴仁县| 喜德县| 洪江市| 许昌市| 杭州市|