Skip to content

MethodSecurityExpressionHandler doesn't allow null to be returned when filtering #19781

Description

@GFriedrich

Describe the bug
I've implemented a custom MethodSecurityExpressionHandler in earlier Spring versions which does some filtering. In the past I've returned null when the incoming filterTarget was null as well. Unfortunately though with adding the new @Nullable annotations to Spring 7 (and me using Kotlin and upgrading to the latest Spring version), I can't do this any longer, as the return type misses a @Nullable annotation. So this is a regression in contrast to previous Spring versions.

I personally think it should be possible to return null from this and it was missed when introducing the annotations to the interface, because the actual calling code on PostFilterAuthorizationMethodInterceptor.invoke allows null to be returned from the filter.

Be aware that this whole problem is also somewhat connected to the issue at #19280
So one could either merge the solution mentioned over there or add the missing annotation mentioned here. Either one or the other would actually work for me.

Thanks for checking. 🙏

To Reproduce
Implement a custom MethodSecurityExpressionHandler and try to return null from the filter method.

Expected behavior
It should be allowed to return null from the filter method.

Sample
https://github.com/GFriedrich/spring-security-issue

  1. See that the code compiles with Spring Boot 3
  2. Update the Spring Boot plugin to 4.x (e.g. 4.1.1) inside the build.gradle.kts
  3. See that the compilation now fails
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions