spring-projects / spring-projects/spring-security
6.5.0-M3 - support configuring the webauthn filter urls
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Expected Behavior
the webauthn filter urls are configurable.
Current Behavior
WebAuthnConfigurer does not support configuration of the webauthn urls and the defaults are used (login/webauthn, /webauthn/...).
Context
being able to configure the urls is especially important when multiple security filter chains are involved (e.g. /api/... vs. /something-else/...) and webauthn should only be enabled for a subset of these security filter chains.
thanks for consideration.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Begin by locating WebAuthnConfigurer and tracing where the login/webauthn and /webauthn/... defaults are applied. Determine the configuration surface needed when multiple security filter chains are used, then add coverage for custom URLs and verify the existing defaults remain compatible.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100