spring-projects / spring-projects/spring-security

Add setPreAuthenticationChecks to AbstractUserDetailsReactiveAuthenticationManager

Open Beginner friendly
#19,275 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Expected Behavior

AbstractUserDetailsReactiveAuthenticationManager should allow customizing the pre-authentication account status checks, the same way its servlet counterpart AbstractUserDetailsAuthenticationProvider does via setPreAuthenticationChecks(UserDetailsChecker).

Current Behavior

The reactive manager holds a private preAuthenticationChecks field and applies it in authenticate():

private UserDetailsChecker preAuthenticationChecks = this::defaultPreAuthenticationChecks;
...
return retrieveUser(username)
        .doOnNext(this.preAuthenticationChecks::check)

but only exposes setPostAuthenticationChecks. The field is private, the default implementation is a private method, and there is no protected getter — so a WebFlux application cannot customize how locked/disabled/expired accounts are checked (e.g. custom error messages or lockout policy) without overriding authenticate() entirely.

Context

The synchronous AbstractUserDetailsAuthenticationProvider exposes both setPreAuthenticationChecks and setPostAuthenticationChecks.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with AbstractUserDetailsReactiveAuthenticationManager.authenticate() and compare it with AbstractUserDetailsAuthenticationProvider.setPreAuthenticationChecks(UserDetailsChecker). Confirm that the reactive manager supports equivalent pre-authentication customization while retaining its default checks, and verify the relevant reactive authentication-manager tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
76/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.