Skip to content

@PostFilter throws an IllegalArgumentException on null return after migrating to @EnableMethodSecurity #19280

Description

@jmeyer2030

Describe the bug
This might be either a bug, or a documentation gap.

On EnableGlobalMethodSecurity, PostFilter on a null return will return null from ExpressionBasedPostInvocationAdvice.

On EnableMethodSecurity, PostFilterAuthorizationMethodInterceptor calls DefaultMethodSecurityExpressionHandler.filter which throws an IllegalArgumentException.

To Reproduce

@Configuration
@EnableMethodSecurity
class SecurityConfig {
}
@Service
class MyService {
    @PostFilter("filterObject != null")
    public List<Object> someMethod() {
        return null;
    }
}

Call "someMethod()". It will throw an exception.

Switch to the legacy configuration:

@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
class SecurityConfig {
}

Call "someMethod()" again. It will return null.

Expected behavior

Either:

  1. EnableMethodSecurity should preserve the legacy behavior from EnableGlobalMethodSecurity and return null when a PostFilter method returns null

or

  1. The migration / PostFilter documentation should state that null return values aren't supported, and that this is different from the legacy EnableGlobalMethodSecurity.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions