{"repo":"pac4j/spring-webmvc-pac4j","free":true,"listed":false,"github":"https://github.com/pac4j/spring-webmvc-pac4j","clone":"git clone https://github.com/pac4j/spring-webmvc-pac4j.git","description":"Security library for Spring Web MVC: OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...","language":"Java","stars":139,"topics":["java","spring-mvc","spring-boot","security","authentication","authorization","cas","oauth","saml","openid-connect"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"The spring-webmvc-pac4j project is an easy and powerful security library for Spring Web MVC / Spring Boot web applications and web services . It supports authentication and authorization, but also logout and advanced features like session fixation and CSRF protection. It's based on the pac4j security engine . It's available under the Apache 2 license. spring-webmvc-pac4j JDK pac4j Spring Usage of Lombok Status --------------------- ----- ------- -------- ----------------- ------------------ version = 8 17 v6 v6+ Yes Production ready version = 7 17 v5 v6 No Production ready version = 5 11 v5 v5 No Production ready version = 4 8 v4 v5 No Production ready Main concepts and components: 1) A client represents an authentication mechanism. It performs the login process and returns a user profile. An indirect client is for web application authentication while a direct client is for web services authentication: &#9656; OpenID Connect - OAuth - SAML - CAS - HTTP - LDAP - SQL - JWT - MongoDB - IP address - Kerberos (SPNEGO) - REST API 2) An authorizer is meant to check authorizations on the authenticated user profile(s) or on the current web context: &#9656; Roles - Anonymous / remember-me / (fully) authenticated - Profile type, attribute - CORS - CSRF - Security headers - IP address, HTTP method 3) A matcher defines whether the SecurityInterceptor must be applied and can be used for additional web processing Directly available via the Pac4jSecurityConfig component: 4) The SecurityInter","default_branch":null,"files":null,"tree":[],"storefront":"/r/pac4j","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/pac4j/spring-webmvc-pac4j/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}