spring-projects / spring-projects/spring-security
Should AuthorizationManager.authorize prohibit returning null
Open
Nobody has claimed this yet.
status: waiting-for-triage
type: enhancement
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Given that we have a rich object being returned here, I wonder if we should prohibit a null value from being returned
For the Reactive side, I wonder if we should prevent an empty Mono from being returned
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the AuthorizationManager.authorize contract and the Reactive authorization path mentioned in the issue. Determine whether null results and empty Mono values should be prohibited, then establish the expected contract and tests before making any change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100