This is an automated email from the ASF dual-hosted git repository.
lprimak pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/shiro-site.git
The following commit(s) were added to refs/heads/asf-staging by this push:
new fc56d01d5 content updates
fc56d01d5 is described below
commit fc56d01d5d2f30e7931d7b739db8c1ce6ed91512
Author: lprimak <[email protected]>
AuthorDate: Thu Apr 30 10:36:17 2026 -0500
content updates
---
.well-known/security.txt | 2 +-
blog/2026/04/community-effort.html | 14 +++++++-------
feed.xml | 10 +++++-----
index.html | 2 +-
jakarta-ee.html | 8 ++++++++
news.html | 2 +-
sitemap.xml | 2 +-
spring-boot.html | 4 ++--
spring-framework.html | 4 ++--
troubleshooting.html | 21 +++++++++++++++++++++
10 files changed, 49 insertions(+), 20 deletions(-)
diff --git a/.well-known/security.txt b/.well-known/security.txt
index f51e2f4df..dba778917 100644
--- a/.well-known/security.txt
+++ b/.well-known/security.txt
@@ -1,5 +1,5 @@
Contact: mailto:[email protected]
-Expires: 2027-04-02T19:43:24Z
+Expires: 2027-04-30T15:35:49Z
Preferred-Languages: en
Canonical: https://shiro.apache.org/.well-known/security.txt
Policy: https://shiro.apache.org/security-reports.html
\ No newline at end of file
diff --git a/blog/2026/04/community-effort.html
b/blog/2026/04/community-effort.html
index db6fc4955..c31460cb2 100644
--- a/blog/2026/04/community-effort.html
+++ b/blog/2026/04/community-effort.html
@@ -29,8 +29,8 @@
<meta name="msvalidate.01" content="0B57EB46CBFAD8FD45008D2DB6B6C68C">
<meta property="og:title" content="Apache Shiro: A New Chapter Driven by
Community | Apache Shiro"/>
- <meta property="article:published_time" content="2026-04-02T00:00:00Z"/>
- <meta name="publish_date" property="og:publish_date"
content="2026-04-02T00:00:00Z"/>
+ <meta property="article:published_time" content="2026-04-29T00:00:00Z"/>
+ <meta name="publish_date" property="og:publish_date"
content="2026-04-29T00:00:00Z"/>
<meta name="twitter:creator" content="@lprimak" />
<meta property="article:author" content="https://www.facebook.com/lprimak"
/>
<meta property="profile:first_name" content="Lenny" />
@@ -38,7 +38,7 @@
<meta property="og:type" content="article"/>
<meta name="twitter:card" content="summary" />
<meta name="twitter:site" content="@ApacheShiro" />
- <meta property="article:modification_time" content="2026-04-02T00:00:00Z"/>
+ <meta property="article:modification_time" content="2026-04-29T00:00:00Z"/>
<meta property="article:tag" content='blog'/>
<meta property="article:tag" content='community'/>
<meta property="article:tag" content='open source'/>
@@ -215,14 +215,14 @@
<p>
<em>Published by <a rel="author"
href="https://twitter.com/@lprimak">Lenny Primak</a> on the
- <time datetime="2026-04-02T00:00:00Z">02nd of April,
2026</time>
+ <time datetime="2026-04-29T00:00:00Z">29th of April,
2026</time>
</em>
</p>
<div id="preamble">
<div class="sectionbody">
<div class="paragraph">
-<p>Apache Shiro has entered a new chapter—one filled with opportunity.</p>
+<p>Apache Shiro has entered a new chapter, one filled with opportunity.</p>
</div>
<div class="paragraph">
<p>For years, Shiro has quietly powered authentication, authorization,
cryptography, and session management for countless applications around the
world. Its simplicity and flexibility made it a favorite among developers who
needed security without unnecessary complexity.</p>
@@ -270,13 +270,13 @@
</ul>
</div>
<div class="paragraph">
-<p>If you rely on Shiro—even indirectly—this is the time to invest in its
future. Financial involvement isn’t just support; it’s a way to ensure the
tools you depend on remain secure, modern, and well-maintained.</p>
+<p>If you rely on Shiro, even indirectly, this is the time to invest in its
future. Financial involvement isn’t just support; it’s a way to ensure the
tools you depend on remain secure, modern, and well-maintained.</p>
</div>
<div class="paragraph">
<p>And if you’re an engineer looking to make an impact, this is a rare chance
to shape the direction of a widely used security framework.</p>
</div>
<div class="paragraph">
-<p>Open source doesn’t disappear when funding changes—it evolves based on who
shows up next.</p>
+<p>Open source doesn’t disappear when funding changes, it evolves based on who
shows up next.</p>
</div>
<div class="paragraph">
<p>Let’s make sure Shiro continues to be a project worth relying on.</p>
diff --git a/feed.xml b/feed.xml
index c21ae08f9..bac4ca961 100644
--- a/feed.xml
+++ b/feed.xml
@@ -4,7 +4,7 @@
<subtitle>Simple. Java. Security.</subtitle>
<link href="https://shiro.apache.org/"/>
<link rel="self" href="https://shiro.apache.org/feed.xml" />
- <updated>2026-04-02T19:43:25Z</updated>
+ <updated>2026-04-30T15:35:50Z</updated>
<author>
<name>Les Hazlewood</name>
@@ -39,7 +39,7 @@
<title>Apache Shiro: A New Chapter Driven by Community</title>
<link href="https://shiro.apache.org/blog/2026/04/community-effort.html"/>
<id>https://shiro.apache.org/blog/2026/04/community-effort.html</id>
- <updated>2026-04-02T00:00:00Z</updated>
+ <updated>2026-04-29T00:00:00Z</updated>
<author>
<name>Lenny Primak</name>
</author>
@@ -47,7 +47,7 @@
<div id="preamble">
<div class="sectionbody">
<div class="paragraph">
-<p>Apache Shiro has entered a new chapter—one filled with
opportunity.</p>
+<p>Apache Shiro has entered a new chapter, one filled with
opportunity.</p>
</div>
<div class="paragraph">
<p>For years, Shiro has quietly powered authentication, authorization,
cryptography, and session management for countless applications around the
world. Its simplicity and flexibility made it a favorite among developers who
needed security without unnecessary complexity.</p>
@@ -95,13 +95,13 @@
</ul>
</div>
<div class="paragraph">
-<p>If you rely on Shiro—even indirectly—this is the time to invest in
its future. Financial involvement isn’t just support; it’s a way to ensure the
tools you depend on remain secure, modern, and well-maintained.</p>
+<p>If you rely on Shiro, even indirectly, this is the time to invest in
its future. Financial involvement isn’t just support; it’s a way to ensure the
tools you depend on remain secure, modern, and well-maintained.</p>
</div>
<div class="paragraph">
<p>And if you’re an engineer looking to make an impact, this is a rare
chance to shape the direction of a widely used security framework.</p>
</div>
<div class="paragraph">
-<p>Open source doesn’t disappear when funding changes—it evolves based
on who shows up next.</p>
+<p>Open source doesn’t disappear when funding changes, it evolves based
on who shows up next.</p>
</div>
<div class="paragraph">
<p>Let’s make sure Shiro continues to be a project worth relying
on.</p>
diff --git a/index.html b/index.html
index 5b9cf0df9..08cbacdc9 100644
--- a/index.html
+++ b/index.html
@@ -309,7 +309,7 @@
<div class="card-body">
<div>
<a href="blog/2026/04/community-effort.html"><h4
class="news-title">Apache Shiro: A New Chapter Driven by Community</h4></a>
- <p><small>by Lenny Primak on 2026-04-02</small></p>
+ <p><small>by Lenny Primak on 2026-04-29</small></p>
</div>
<div>
<a href="blog/2026/02/apache-shiro-3-alpha-1-released.html"><h4
class="news-title">3.0.0-alpha-1 available</h4></a>
diff --git a/jakarta-ee.html b/jakarta-ee.html
index 651dd6b6c..45f8322a3 100644
--- a/jakarta-ee.html
+++ b/jakarta-ee.html
@@ -638,6 +638,14 @@ Any Shiro principal object can be injected if annotated by
<code>@Principal</cod
<pre class="highlightjs highlight"><code class="language-properties hljs"
data-lang="properties">authc.useRemembered = true</code></pre>
</div>
</div>
+<div class="paragraph">
+<p>RememberMe uses secure cookies by default. If you are running in non-HTTPS
environment, you can disable secure cookies in Jakarta Faces' development mode
only by adding the following to <code>shiro.ini</code> (this is the recommended
configuration, but make sure production is running in Faces production
mode):</p>
+</div>
+<div class="listingblock">
+<div class="content">
+<pre class="highlightjs highlight"><code class="language-properties hljs"
data-lang="properties">securityManager.rememberMeManager.secureInDevMode =
false</code></pre>
+</div>
+</div>
</div>
<div class="sect3">
<h4 id="rate_limiting">Rate limiting: Automatic delay when login failed</h4>
diff --git a/news.html b/news.html
index d86784ca4..2e6de4b49 100644
--- a/news.html
+++ b/news.html
@@ -199,7 +199,7 @@
<h4>April 2026</h4>
<ul>
- <li>02 - <a href="blog/2026/04/community-effort.html">Apache Shiro: A New
Chapter Driven by Community</a></li>
+ <li>29 - <a href="blog/2026/04/community-effort.html">Apache Shiro: A New
Chapter Driven by Community</a></li>
</ul>
<h4>February 2026</h4>
<ul>
diff --git a/sitemap.xml b/sitemap.xml
index a63835aa8..8101da785 100644
--- a/sitemap.xml
+++ b/sitemap.xml
@@ -286,7 +286,7 @@
</url>
<url>
<loc>https://shiro.apache.org/blog/2026/04/community-effort.html</loc>
- <lastmod>2026-04-02</lastmod>
+ <lastmod>2026-04-29</lastmod>
</url>
<url>
<loc>https://shiro.apache.org/blog/2026/02/apache-shiro-3-alpha-1-released.html</loc>
diff --git a/spring-boot.html b/spring-boot.html
index e9750dc50..678c27660 100644
--- a/spring-boot.html
+++ b/spring-boot.html
@@ -587,12 +587,12 @@ protected CacheManager cacheManager() {
</tr>
<tr>
<td class="tableblock halign-left valign-top"><p
class="tableblock">shiro.rememberMeManager.cookie.path</p></td>
-<td class="tableblock halign-left valign-top"><p
class="tableblock">null</p></td>
+<td class="tableblock halign-left valign-top"><p
class="tableblock">ROOT_PATH</p></td>
<td class="tableblock halign-left valign-top"><p class="tableblock">RememberMe
cookie path</p></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><p
class="tableblock">shiro.rememberMeManager.cookie.secure</p></td>
-<td class="tableblock halign-left valign-top"><p
class="tableblock"><code>false</code></p></td>
+<td class="tableblock halign-left valign-top"><p
class="tableblock"><code>true</code></p></td>
<td class="tableblock halign-left valign-top"><p class="tableblock">RememberMe
cookie secure flag</p></td>
</tr>
<tr>
diff --git a/spring-framework.html b/spring-framework.html
index 9a30e5830..b05122dbd 100644
--- a/spring-framework.html
+++ b/spring-framework.html
@@ -891,12 +891,12 @@ age</p></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><p
class="tableblock">shiro.rememberMeManager.cookie.path</p></td>
-<td class="tableblock halign-left valign-top"><p
class="tableblock">null</p></td>
+<td class="tableblock halign-left valign-top"><p
class="tableblock">ROOT_PATH</p></td>
<td class="tableblock halign-left valign-top"><p class="tableblock">RememberMe
cookie path</p></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><p
class="tableblock">shiro.rememberMeManager.cookie.secure</p></td>
-<td class="tableblock halign-left valign-top"><p
class="tableblock"><code>false</code></p></td>
+<td class="tableblock halign-left valign-top"><p
class="tableblock"><code>true</code></p></td>
<td class="tableblock halign-left valign-top"><p class="tableblock">RememberMe
cookie
secure flag</p></td>
</tr>
diff --git a/troubleshooting.html b/troubleshooting.html
index cd4feaa2f..8f7111126 100644
--- a/troubleshooting.html
+++ b/troubleshooting.html
@@ -917,6 +917,27 @@ subject.isRemembered();</code></pre>
</div>
</div>
</li>
+<li>
+<p><strong>Browser cookie issues</strong>: Ensure the browser accepts cookies
and that there are no domain/path mismatches.
+By default, Shiro’s Remember Me cookie is HTTP-only and secure. If
you’re testing in a non-HTTPS environment, you may need to adjust the
secure flag for testing purposes.
+You can use system property to control this behavior. Set
<code>org.apache.shiro.rememberMe.secure.disabled</code> to <code>true</code>
to disable the secure flag on the Remember Me cookie for testing.
+You can also configure this in your <code>shiro.ini</code>:</p>
+<div class="listingblock">
+<div class="content">
+<pre class="highlightjs highlight"><code class="language-ini hljs"
data-lang="ini">[main]
+securityManager.rememberMeManager.cookie.secure = false</code></pre>
+</div>
+</div>
+<div class="paragraph">
+<p>For Jakarta EE applications, the secure flag is enabled by default. You can
disable it for testing purposes in Jakarta Faces' Development mode only by
setting the following in your shiro.ini:</p>
+</div>
+<div class="listingblock">
+<div class="content">
+<pre class="highlightjs highlight"><code class="language-ini hljs"
data-lang="ini">[main]
+securityManager.rememberMeManager.secureInDevMode = false</code></pre>
+</div>
+</div>
+</li>
</ol>
</div>
</div>