spring-projects / spring-projects/spring-security
Method Security does not switch to Interface Proxies for final Classes
Open
@evgeniycheban is already working on this.
Since Apr 1, 2025.
in: core
type: bug
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
If Spring Security's method security is used on a final class that implements an interface it fails. Instead it should create an interface based proxy
For example:
public interface BankAccountService {
BankAccount findById(int id);
}
@Service
public final class BankAccountServiceImpl implements BankAccountService {
@PostAuthorize("returnObject?.owner == authentication?.name")
@Override
public BankAccount findById(int id) {
return null;
}
}
@SpringBootApplication
@EnableMethodSecurity
public class BankAccountApplication {
public static void main(String[] args) {
SpringApplication.run(BankAccountApplication.class, args);
}
}
// fails due to final class being proxied as class based proxy instead of interface based proxy
@SpringBootTest
class BankAccountServiceTest {
@Autowired
BankAccountService accounts;
@Test
void loads() {}
}
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.