spring-projects / spring-projects/spring-security

SEC-3095: Add Ant multi-pattern support

Open
#3,302 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: config in: core in: web type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Fabien Baligand (Migrated from SEC-3095) said:

This would be great to add ant multi-pattern support.

This would allow such a configuration :

<security:http pattern="/login, /error/**, /resources/**" security="none"/>

Ant itself supports it out-of-the-box.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating Spring Security's XML security:http configuration handling for the pattern attribute and compare it with Ant's multi-pattern behavior. Use the example configuration in the issue as the acceptance case; done means comma-separated patterns such as /login, /error/, and /resources/ are accepted for security="none".

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.