spring-projects / spring-projects/spring-security

Spring Security's `Filter`s and `WebFilter`s Automatically Registered by Spring Boot

Open
#16,222 5 comments 0 reactions 1 assignee View on GitHub

@rwinch is already working on this.

Since Dec 5, 2024.

in: web type: bug
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Spring Security reuses Filter and WebFilter APIs for security-based controller based logic within a Spring Security application. The Security Filter's should be registered with FilterChainProxy and WebFilters with WebFilterChainProxy.

However, Spring Boot's auto configuration will automatically register any Filter or WebFilter with the application. This behavior surprises users when they create a Filter or WebFilter bean to register with Spring security and it and causes problems due to ordering and duplicate invocations.

We should make it so that this works correctly out of the box for users.

Related https://github.com/spring-projects/spring-boot/issues/16500

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.