6.2.2
⭐ New Features
- Configuration examples in docs are out of date #14392
🪲 Bug Fixes
- "Span wasn't started - an observation must be started (not only created)" (Micrometer) due to observation handling in Spring Security Web? #14568
HandlerMappingIntrospectorRequestTransformer
is registered twice in AOT #14367OAuth2AuthorizationExchange
is not serializable #14405WebTestUtilsTestRuntimeHints
should implementRuntimeHintsRegistrar
#14468- Application context fails to load: Couldn't find FilterChainProxy #14380
- Back-Channel Logout should use localhost for internal logout request #14553
- Cannot configure
SecurityContextRepository
inCasAuthenticationFilter
#14536 - Documentation about configuring SecuritySocketAcceptorInterceptor in Spring Boot is confusing #14348
- fix typo in anonymous.adoc #14424
- fix: typo in Authentication Architecture ProviderManager #14448
- Missing native-image reflection hint for
HandlerMappingIntrospectorCachFilterFactoryBean
#14377 - Missing native-image reflection hint for CsrfTokenRequestAttributeHandler$SupplierCsrfToken #14470
- ReactiveMethodSecurityConfiguration is initialized prematurely when the context contains a BeanPostProcessor #14350
- SAML relying party logout filter is always ordered last #14551
- Spring Security 6.2 defaults to InMemoryOidcSessionRegistry causing memory leaks in distributed systems with external session storage #14558
- Test using
@WithMockUser
fails with 401 UNAUTHORIZED with 3.2 #14207 - Typo: Update authorize-http-requests.adoc #14563
- Unexpected Exception Handling in NimbusReactiveJwtDecoder decode Method #14496
- X-Xss-Protection header "1; mode=block" differs in Servlet and Reactive #14346
🔨 Dependency Upgrades
- Bump com.fasterxml.jackson:jackson-bom from 2.15.3 to 2.15.4 #14617
- Bump Gamesight/slack-workflow-status from 1.2.0 to 1.3.0 #14582
- Bump Gradle Wrapper from 8.5 to 8.6 #14547
- Bump gradle/gradle-build-action from 2 to 3 #14503
- Bump io-spring-javaformat from 0.0.40 to 0.0.41 #14439
- Bump io.micrometer:micrometer-observation from 1.12.1 to 1.12.2 #14429
- Bump io.micrometer:micrometer-observation from 1.12.2 to 1.12.3 #14589
- Bump io.mockk:mockk from 1.13.8 to 1.13.9 #14412
- Bump io.projectreactor:reactor-bom from 2023.0.1 to 2023.0.2 #14430
- Bump io.projectreactor:reactor-bom from 2023.0.2 to 2023.0.3 #14612
- Bump io.spring.ge.conventions from 0.0.14 to 0.0.15 #14463
- Bump org-aspectj from 1.9.21 to 1.9.21.1 #14605
- Bump org-eclipse-jetty from 11.0.18 to 11.0.19 #14354
- Bump org-eclipse-jetty from 11.0.19 to 11.0.20 #14518
- Bump org.apereo.cas.client:cas-client-core from 4.0.3 to 4.0.4 #14440
- Bump org.jetbrains.kotlin:kotlin-bom from 1.9.21 to 1.9.22 #14364
- Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.21 to 1.9.22 #14363
- Bump org.junit:junit-bom from 5.10.1 to 5.10.2 #14543
- Bump org.slf4j:slf4j-api from 2.0.10 to 2.0.11 #14422
- Bump org.slf4j:slf4j-api from 2.0.11 to 2.0.12 #14554
- Bump org.slf4j:slf4j-api from 2.0.9 to 2.0.10 #14387
- Bump org.springframework.data:spring-data-bom from 2023.1.1 to 2023.1.2 #14455
- Bump org.springframework.data:spring-data-bom from 2023.1.2 to 2023.1.3 #14624
- Bump org.springframework.ldap:spring-ldap-core from 3.2.1 to 3.2.2 #14616
- Bump org.springframework:spring-framework-bom from 6.1.2 to 6.1.3 #14454
- Bump org.springframework:spring-framework-bom from 6.1.3 to 6.1.4 #14615
- Bump slackapi/slack-github-action from 1.24.0 to 1.25.0 #14504
- Bump spring-io/spring-github-workflows from eaf17a1890b1ef1b337f015d6eb263baaf8c6dab to 1e8b0587a1f4f01697f9753fa3339c3e0d30f396 #14583
❤️ Contributors
Thank you to all the contributors who worked on this release:
@Amitmahato, @andreasbuechel, @boulce, and @dependabot[bot]