Skip to content

OneTimeTokenAuthenticationProvider authenticate method setDetails call #16856

Description

@aurelo

Describe the bug
OneTimeTokenAuthenticationProvider does not set Principal correctly

To Reproduce
Log in via OneTimeToken with custom UserDetails with i.e. email additional field

Expected behavior
OneTimeTokenAuthenticationToken should have email field present in Principal

Bug

By my opinion bug is in line:

authenticated.setDetails(otpAuthenticationToken.getDetails());

otpAuthenticationToken is unathenticated token and does not have details!

line should probably be:

authenticated.setDetails(user);

Activity

  1. jsunsoftware commented on Oct 9, 2026

    @jsunsoftware

    This looks like the same root cause as #19863 : OneTimeTokenAuthenticationConverter never sets details on the
    OneTimeTokenAuthenticationToken, so the provider copies null. Details are meant to describe the request
    (WebAuthenticationDetails), and the user is already available as the principal, so setDetails(user) would not be the
    right fix. #19863 has a reproduction and a proposed change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions