spring-projects / spring-projects/spring-security
Registration of SecurityFilterChain via WebSecurityCustomizer results in UnreachableFilterChainException
@jzheaux is already working on this.
Since Aug 22, 2025.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Describe the bug
Spring Security automatically adds a default SecurityFilterChain when no SecurityFilterChain bean has been configured. This conflicts with SecurityFilterChains added via a WebSecurityCustomizer resulting in an UnreachableFilterChainException at application startup because the automatically configured filter chain matches any request.
To Reproduce
@Configuration(proxyBeanMethods = false)
public class SecurityConfiguration {
@Bean
public WebSecurityCustomizer security(HttpSecurity http) throws Exception {
http.authorizeHttpRequests(registry -> registry.anyRequest().permitAll());
var chain = http.build();
return web -> web.addSecurityFilterChainBuilder(() -> chain);
}
}
Expected behavior
The default SecurityFilterChain should only be added to the WebSecurity if no SecurityBuilder<? extends SecurityFilterChain> is present after adding all SecurityFilterChain beans and applying all WebSecurityCustomizers.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.