Repository navigation
(doc issue) permitAll/denyAll listed as "methods" in docs but are actually fields in SecurityExpressionRoot #19728
Description
Activity
- addedstatus: waiting-for-triageAn issue we've not yet triagedAn issue we've not yet triagedtype: bugA general bugA general bug
on Sep 15, 2026 I looked into this and I think both readings are partly right.
SecurityExpressionRoothas the two fields, and it also haspermitAll()anddenyAll()methods fromSecurityExpressionOperations:public final boolean permitAll = true; public final boolean denyAll = false; @Override public final boolean permitAll() { return isGranted(this.authorizationManagerFactory.permitAll()); } @Override public final boolean denyAll() { return isGranted(this.authorizationManagerFactory.denyAll()); }
So
@PreAuthorize("permitAll")reads the field and@PreAuthorize("permitAll()")calls the method. The field Javadoc says it's there to allow the bare"permitAll"expression, and the example a little further down the same page uses that form (@PreAuthorize("denyAll")).With the default
AuthorizationManagerFactoryboth forms give the same answer. The one difference I found is that only the method form goes through the factory, so if someone sets a custom factory that overridespermitAll()ordenyAll(), the bare form won't pick that up.For the docs, a short note under the list saying
permitAllanddenyAllwork both with and without parentheses might clear this up. I'm happy to open a PR for that if the team thinks it's worth it.Thanks for looking into this, @Akhil-1527. Your explanation helped me understand the difference between the
permitAll/denyAllfields and thepermitAll()/denyAll()methods.While reading around, I noticed the same list also appears in the HTTP SpEL section of the reference docs, in case it's useful to cover both places:
spring-security/docs/modules/ROOT/pages/servlet/authorization/authorize-http-requests.adoc
Lines 807 to 809 in c2270bb
What follows is a quick overview of the most common methods: * `permitAll` - The request requires no authorization to be invoked; note that in this case, xref:servlet/authentication/architecture.adoc#servlet-authentication-authentication[the `Authentication`] is never retrieved from the session Also, in that section the
authenticationandprincipaldescriptions say "associated with this method invocation". Since that page is about HTTP requests, I wonder if it was meant to say "this request" instead:spring-security/docs/modules/ROOT/pages/servlet/authorization/authorize-http-requests.adoc
Lines 819 to 820 in c2270bb
* `authentication` - The `Authentication` instance associated with this method invocation * `principal` - The `Authentication#getPrincipal` associated with this method invocation
In the Method Security reference docs, under "Using Authorization Expression Fields and Methods,"
and
permitAllanddenyAllare listed under the quick "overview of the most common methods".However, in
SecurityExpressionRoot, these are declared as fields, not methods: