Describe the bug
I've implemented a custom MethodSecurityExpressionHandler in earlier Spring versions which does some filtering. In the past I've returned null when the incoming filterTarget was null as well. Unfortunately though with adding the new @Nullable annotations to Spring 7 (and me using Kotlin and upgrading to the latest Spring version), I can't do this any longer, as the return type misses a @Nullable annotation. So this is a regression in contrast to previous Spring versions.
I personally think it should be possible to return null from this and it was missed when introducing the annotations to the interface, because the actual calling code on PostFilterAuthorizationMethodInterceptor.invoke allows null to be returned from the filter.
Be aware that this whole problem is also somewhat connected to the issue at #19280
So one could either merge the solution mentioned over there or add the missing annotation mentioned here. Either one or the other would actually work for me.
Thanks for checking. 🙏
To Reproduce
Implement a custom MethodSecurityExpressionHandler and try to return null from the filter method.
Expected behavior
It should be allowed to return null from the filter method.
Sample
https://github.com/GFriedrich/spring-security-issue
- See that the code compiles with Spring Boot 3
- Update the Spring Boot plugin to 4.x (e.g. 4.1.1) inside the
build.gradle.kts
- See that the compilation now fails
Describe the bug
I've implemented a custom
MethodSecurityExpressionHandlerin earlier Spring versions which does some filtering. In the past I've returnednullwhen the incomingfilterTargetwasnullas well. Unfortunately though with adding the new@Nullableannotations to Spring 7 (and me using Kotlin and upgrading to the latest Spring version), I can't do this any longer, as the return type misses a@Nullableannotation. So this is a regression in contrast to previous Spring versions.I personally think it should be possible to return
nullfrom this and it was missed when introducing the annotations to the interface, because the actual calling code onPostFilterAuthorizationMethodInterceptor.invokeallowsnullto be returned from the filter.Be aware that this whole problem is also somewhat connected to the issue at #19280
So one could either merge the solution mentioned over there or add the missing annotation mentioned here. Either one or the other would actually work for me.
Thanks for checking. 🙏
To Reproduce
Implement a custom MethodSecurityExpressionHandler and try to return null from the
filtermethod.Expected behavior
It should be allowed to return
nullfrom thefiltermethod.Sample
https://github.com/GFriedrich/spring-security-issue
build.gradle.kts