spring-projects / spring-projects/spring-security

JwtAuthenticationToken.principal and JwtAuthenticationToken.Builder.principal types do not match

Open
#19,333 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage type: bug
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

When I create a JwtAuthenticationToken through its constructor, I can pass my own custom principal class (which is not required to implement any interface or extend any class).

If I create a JwtAuthenticationToken through its builder, the principal must be of type Jwt.

Why are the requirements on the principal type different? Can the types be aligned?

Also, why does BearerTokenAuthentication force the principal to implement OAuth2AuthenticatedPrincipal, it would be great if I could use my own custom princpal class (without any type requirement) like I do with JwtAuthenticationToken.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by comparing the principal type exposed by JwtAuthenticationToken's constructor with the type required by JwtAuthenticationToken.Builder.principal. Then inspect BearerTokenAuthentication's OAuth2AuthenticatedPrincipal requirement and the surrounding authentication entry points. Done means the principal type requirements are intentionally aligned or clearly resolved for both APIs, with behavior verified by the relevant existing tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.