Apache Shiro security framework releases 3.0.0
The Apache Shiro team is pleased to announce the release of Apache Shiro version 3.0.0.
This release is available for download now.
Release Highlights
This is a new major release of Apache Shiro, with many new features and improvements, culminating more than two years of work.
- JDK 17 is the new minimum baseline
- Jakarta EE 9/10/11+ (no javax.* namespace)
- Spring 6/7+ and SpringBoot 3/4+
- Guice 7/8+
- Using Java Scoped values for Subject and SecurityManager instead of ThreadLocals on JDK 25+
- Improved thread-safety of Shiro-native sessions (SimpleSession, SimpleSessionFactory, CachingSessionDAO)
Breaking API Changes
- Made default implementation of PrincipalCollection immutable (ImmutablePrincipalCollection)
Security Enhancements
- Case-insensitive path matching is now enabled by default (hardened by default)
- Added NoAccessFilter and add it to the default filter chain (breaking change, hardened-by-default)
- Enable CORS preflight requests by default
End-of-life notice
Apache Shiro 1.x and 2.x are now considered end-of-life. If support for these versions is required, please check Commercial Support
Thank you to the following contributors!
All changes
You can learn more on GitHub, Release 3.0.0.
Download
Download and verification instructions are available on our download page.
Documentation
For more information on Shiro, please read the documentation.
Enjoy!
The Apache Shiro Team
评论
?
参与讨论