The following items are related to Spring Security's interaction with Web-based applications:
- #3812: Jackson support
- #4116: Referrer policy
- #3938: Added HTTP response splitting prevention
- #3949: Added bean reference support to @AuthenticationPrincipal
- #3978: Support for Standford WebAuth and Shibboleth using the newly added RequestAttributeAuthenticationFilter
- #4076: Document proxy server configuration
- #3795: ConcurrentSessionFilter supports InvalidSessionStrategy
- #3904: Added CompositeLogoutHandler