spring-security
spring-security copied to clipboard
Enabling authenticationIsRequired to be overridden for custom checks.…
Fixes BasicAuthenticationFilter skips re-authentication if username changes and Authentication object is not UsernamePasswordAuthenticationToken #10347
@shazin sorry for the delay on this PR. Can you please adjust to align with @rwinch's comment on the original ticket?
@shazin, just checking to see if you saw the comment above and are able to update this PR to remove existingAuth instanceof UsernamePasswordAuthenticationToken as suggested in @rwinch's comment?
Merged via 1e0e9a2c98d6f37aa8989801a75fb434cd953c06 along with e0e6467d9b1203b38d152b40281265e0816af8be