spring-projects / spring-projects/spring-security
JwtAuthenticationToken.principal and JwtAuthenticationToken.Builder.principal types do not match
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
When I create a JwtAuthenticationToken through its constructor, I can pass my own custom principal class (which is not required to implement any interface or extend any class).
If I create a JwtAuthenticationToken through its builder, the principal must be of type Jwt.
Why are the requirements on the principal type different? Can the types be aligned?
Also, why does BearerTokenAuthentication force the principal to implement OAuth2AuthenticatedPrincipal, it would be great if I could use my own custom princpal class (without any type requirement) like I do with JwtAuthenticationToken.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the principal type exposed by JwtAuthenticationToken's constructor with the type required by JwtAuthenticationToken.Builder.principal. Then inspect BearerTokenAuthentication's OAuth2AuthenticatedPrincipal requirement and the surrounding authentication entry points. Done means the principal type requirements are intentionally aligned or clearly resolved for both APIs, with behavior verified by the relevant existing tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100