spring-projects / spring-projects/spring-security

Expose default success/error handlers in OAuth2AuthorizationEndpointFilter

Open
#18,261 3 comments 0 reactions 1 assignee View on GitHub

@jgrandja is already working on this.

Since Dec 9, 2025.

in: oauth2 type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Expected Behavior
The default behaviour of the AuthenticationSuccessHandler and AuthenticationFailureHandlers should be acessible, so that they can be extended and/or composed without having to copy-paste them from the current source code.

Current Behavior
In OAuth2AuthorizationEndpointFilter, for example, both handlers are private method references, with no getters defined either.

Context
I wanted to change the error page handler when the redirectUri cannot be used. This was easily possible in the previous implementation.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.