Skip to content

Fix method chaining in ServerHttpSecurity.HeaderSpec.ContentSecurityPolicySpec #19843

Description

@jzheaux

In ServerHttpSecurity.HeaderSpec.ContentSecurityPolicySpec, reportOnly(boolean) and policyDirectives(String) return HeaderSpec instead of ContentSecurityPolicySpec. That prevents method chaining inside the lambda, unlike the servlet ContentSecurityPolicyConfig (and unlike the newer nonceAttributeName(...), exchangeMatcher(...) and exchangeMatchers(...) methods from #18499, which return ContentSecurityPolicySpec).

Changing a return type is not binary compatible, so this likely needs new methods plus deprecation of the existing ones. @ziqin explored this in #18499 (reportOnly() and directives(String) on ContentSecurityPolicySpec) and noted the naming inconsistency with the servlet and Kotlin DSLs; it was deferred so that #18499 could stay focused on nonce support.

Happy to review a pull request for this.

Activity

  1. ziqin commented on Oct 9, 2026

    @ziqin
    Contributor

    Similar return type problems also exist in some other inner ...Spec classes of ServerHttpSecurity. They were not updated during the v6 to v7 migration period probably because there was effectively only one configuration method in those classes, which implies that no chaining problem existed. However, if any new configuration method is added to those Spec classes, similar problems that blocks method chaining would be raised.

  2. ziqin commented on Oct 9, 2026

    @ziqin
    Contributor

    Deprecated HeaderSpec#featurePolicy(String) and FeaturePolicySpec#and() methods could also be cleaned up in v7.x.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    in: configAn issue in spring-security-configtype: enhancementA general enhancement

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions