Skip to content

HttpSecurityDsl should expose underlying HttpSecurity #19834

Description

@ilia1243

Expected Behavior

HttpSecurityDsl should expose underlying HttpSecurity through public HttpSecurityDsl.http field.

https://github.com/spring-projects/spring-security/blob/7.1.1/config/src/main/kotlin/org/springframework/security/config/annotation/web/HttpSecurityDsl.kt#L82

Current Behavior

HttpSecurityDsl.http is private, but it is implicitly exposed through HttpSecurityDsl.with().

Context

Let some library provide a utility function that configures HttpSecurity using its built-in features (csrf, authorizeHttpRequests, etc.).

There is currently no stable way to provide the same utility in Kotlin DSL without code duplication.

HttpSecurityDsl already exposes underlying HttpSecurity through HttpSecurityDsl.with().

https://github.com/spring-projects/spring-security/blob/7.1.1/config/src/main/kotlin/org/springframework/security/config/annotation/web/HttpSecurityDsl.kt#L260

So the desired functionality can be implemented in this way:

fun HttpSecurityDsl.someUtilityDsl() {
    class NoOp : AbstractHttpConfigurer<NoOp, HttpSecurity>()
    someUtility(with(NoOp())!!)
}

This is definitely not the expected use of HttpSecurityDsl.

Is it possible to make the HttpSecurityDsl.http property explicitly public instead?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions