Describe the bug
This might be either a bug, or a documentation gap.
On EnableGlobalMethodSecurity, PostFilter on a null return will return null from ExpressionBasedPostInvocationAdvice.
On EnableMethodSecurity, PostFilterAuthorizationMethodInterceptor calls DefaultMethodSecurityExpressionHandler.filter which throws an IllegalArgumentException.
To Reproduce
@Configuration
@EnableMethodSecurity
class SecurityConfig {
}
@Service
class MyService {
@PostFilter("filterObject != null")
public List<Object> someMethod() {
return null;
}
}
Call "someMethod()". It will throw an exception.
Switch to the legacy configuration:
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
class SecurityConfig {
}
Call "someMethod()" again. It will return null.
Expected behavior
Either:
- EnableMethodSecurity should preserve the legacy behavior from EnableGlobalMethodSecurity and return null when a PostFilter method returns null
or
- The migration / PostFilter documentation should state that null return values aren't supported, and that this is different from the legacy EnableGlobalMethodSecurity.
Describe the bug
This might be either a bug, or a documentation gap.
On EnableGlobalMethodSecurity, PostFilter on a null return will return null from ExpressionBasedPostInvocationAdvice.
On EnableMethodSecurity, PostFilterAuthorizationMethodInterceptor calls DefaultMethodSecurityExpressionHandler.filter which throws an IllegalArgumentException.
To Reproduce
Call "someMethod()". It will throw an exception.
Switch to the legacy configuration:
Call "someMethod()" again. It will return null.
Expected behavior
Either:
or