spring-projects / spring-projects/spring-security
SEC-2155: @Secured annotation and Scala controller
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Dmitry Stropaloff (Migrated from SEC-2155) said:
In an annotation-driven spring project, if @Secured annotation was added to a class or method of a spring scala controller (annotated with @Controller and @RequestMapping) – such class will disappear from URL mapping. No exceptions or warnings can be found in the log (even with DEBUG level). If securing is done within xml configuration ("intercept-url" tag) – all works just fine. Code sample and full description is available via reference URL (StackOverflow).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no repository file or test. Start by reproducing the annotation-driven setup with a Scala controller using @Controller, @RequestMapping, and @Secured, then compare it with the XML intercept-url configuration. Done means the secured controller remains in URL mappings without warnings or exceptions, with regression coverage added.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, scala, spring
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 28/100