Joe Grandja
Joe Grandja is a core committer on the Spring Security team. He has been leading the efforts in building the next generation of OAuth2 and OpenID Connect support in Spring Security and Spring Authorization Server.
With over 25 years of industry experience, Joe has been a Solution Architect, a Software Engineer, a Team Lead, and a Consultant. His past experience has been mainly focused in the Financial Services sector in the Toronto, Canada, area. He has designed, built, and delivered enterprise grade banking applications and platforms in the Personal and Commercial and Brokerage and Investing divisions. He has worked closely with the InfoSec teams within banks to ensure security and regulatory compliance.
Recent Blog posts by Joe Grandja
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 0.4.0-M1. You can download it from repo.spring.io milestone repository by using the module coordinates: See the release notes for complete details. To get started using Spring Authorization Server, see the Getting Started chapter of the reference documentation and the samples to become familiar with setup and configuration. We would love to gather your feedback as we strive to improve and build upon this release. Project Page | GitHub Issues | ZenHub…
Spring Authorization Server 1.0.0-M1 available now
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 1.0.0-M1. You can download it from repo.spring.io milestone repository by using the module coordinates: See the release notes for complete details. To get started using Spring Authorization Server, see the Getting Started chapter of the reference documentation and the samples to become familiar with setup and configuration. We would love to gather your feedback as we strive to improve and build upon this release. Project Page | GitHub Issues | ZenHub…
Spring Authorization Server Is Going 1.0
We are excited to announce that we’ve started preparing for Spring Authorization Server 1.0 with plans to release the GA version in November 2022. It has been just over two years since we initially announced this new project, and we have come a long way since its initial development. The project has a full feature set, and the APIs have stabilized and matured over this time. A lot of effort and care was put into this project to ensure that it can grow and adapt over the next few years. Spring Authorization Server 1.0 will be based on Spring Security 6.0, which will be based off of Spring…
Spring Authorization Server 0.3.1 available now
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 0.3.1. You can download it from Maven Central by using the module coordinates: See the release notes for complete details. This release includes downgrading to JDK 1.8 baseline along with some minor enhancements and bug fixes. To get started using Spring Authorization Server, see the Getting Started chapter of the reference documentation and the samples to become familiar with setup and configuration. We would love to gather your feedback as we strive to…
Spring Security 5.7.2 and 5.6.6 available now
On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Security 5.7.2 and 5.6.6 are available now. You can find more details about the respective releases here and here.
Spring Security OAuth reaches End-of-Life
The Spring Security OAuth and Spring Security OAuth Boot 2 auto-configuration projects have reached end of life. The Spring Security OAuth project has been replaced by the Client and Resource Server support provided by Spring Security and the Authorization Server support provided by Spring Authorization Server.
CVE report published for Spring Security OAuth
We have released Spring Security OAuth 2.5.2 to address the following CVE report. CVE-2022-22969: Denial-of-Service (DoS) in spring-security-oauth2 This vulnerability exposes OAuth 2.0 Client applications only. Please review the information in the CVE report and upgrade immediately.
Spring Authorization Server 0.2.3 available now
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 0.2.3. You can download it from Maven Central by using the module coordinates: See the release notes for complete details. To get started using Spring Authorization Server, see the sample to become familiar with setup and configuration. We would love to gather your feedback as we strive to improve and build upon this release. Project Page | GitHub Issues | ZenHub Board
Spring Authorization Server 0.2.2 available now
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 0.2.2. You can download it from Maven Central by using the module coordinates: See the release notes for complete details. To get started using Spring Authorization Server, see the sample to become familiar with setup and configuration. We would love to gather your feedback as we strive to improve and build upon this release. Project Page | GitHub Issues | ZenHub Board
Spring Authorization Server 0.2.1 available now
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 0.2.1. You can download it from Maven Central by using the module coordinates: See the release notes for complete details. To get started using Spring Authorization Server, see the sample to become familiar with setup and configuration. We would love to gather your feedback as we strive to improve and build upon this release. Project Page | GitHub Issues | ZenHub Board