spring-projects / spring-projects/spring-security

Method Security does not switch to Interface Proxies for final Classes

Open
#16,707 5 comments 0 reactions 2 assignees View on GitHub

@evgeniycheban is already working on this.

Since Apr 1, 2025.

in: core type: bug
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

If Spring Security's method security is used on a final class that implements an interface it fails. Instead it should create an interface based proxy

For example:

public interface BankAccountService {
	BankAccount findById(int id);
}

@Service
public final class BankAccountServiceImpl implements BankAccountService {
	@PostAuthorize("returnObject?.owner == authentication?.name")
	@Override
	public BankAccount findById(int id) {
		return null;
	}
}

@SpringBootApplication
@EnableMethodSecurity
public class BankAccountApplication {

	public static void main(String[] args) {
		SpringApplication.run(BankAccountApplication.class, args);
	}

}

// fails due to final class being proxied as class based proxy instead of interface based proxy
@SpringBootTest
class BankAccountServiceTest {
	@Autowired
	BankAccountService accounts;

	@Test
	void loads() {}
}

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.