Describe the bug
Since version 7.1.0, the method matches of the class Argon2PasswordEncoder uses the class org.springframework.util.StringUtils. However, this class is missing from the jar file downloaded my Maven, causing a java.lang.NoClassDefFoundError to be thrown.
To Reproduce
I've included an example below.
Expected behavior
The class org.springframework.util.StringUtils should be packaged so that no java.lang.NoClassDefFoundError is thrown
Sample
This example was created by Google AI and slightly edited by me (the of this report was not written by AI).
Create this pom.xml
<project xmlns="http://apache.org"
xmlns:xsi="http://w3.org"
xsi:schemaLocation="http://apache.org http://apache.org">
<modelVersion>4.0.0</modelVersion>
<groupId>com.example</groupId>
<artifactId>argon2-demo</artifactId>
<version>1.0-SNAPSHOT</version>
<properties>
<maven.compiler.source>17</maven.compiler.source>
<maven.compiler.target>17</maven.compiler.target>
</properties>
<dependencies>
<!-- The core Spring Security Crypto library -->
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-crypto</artifactId>
<version>7.1.0</version>
</dependency>
<!-- Required runtime dependency for Argon2 support -->
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcprov-jdk18on</artifactId>
<version>1.86</version>
</dependency>
<!-- Required because spring-security-crypto uses commons-logging internally -->
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-jcl</artifactId>
<version>6.2.19</version>
</dependency>
</dependencies>
</project>
Create src/main/java/App.java:
import org.springframework.security.crypto.argon2.Argon2PasswordEncoder;
public class App {
public static void main(String[] args) {
// Initialize the default Argon2 encoder
// Default parameters: salt length 16, hash length 32, parallelism 1, memory 16384, iterations 2
Argon2PasswordEncoder encoder = Argon2PasswordEncoder.defaultsForSpringSecurity_v5_8();
String rawPassword = "mySecurePassword123";
// 1. Hash the password (this automatically handles salt generation)
String hashedPassword = encoder.encode(rawPassword);
System.out.println("Encoded Hashed Password: " + hashedPassword);
// 2. Verify a matching password
boolean isMatch = encoder.matches(rawPassword, hashedPassword);
System.out.println("Password Match Status: " + isMatch); // true
// 3. Verify a wrong password
boolean isWrongMatch = encoder.matches("wrongPassword", hashedPassword);
System.out.println("Wrong Password Match Status: " + isWrongMatch); // false
}
}
Then run
mvn compile exec:java -Dexec.mainClass="App"
When using version 7.1.0 or 7.1.1, this will error as described above, while with version 7.0.7, this will succeed.
Describe the bug
Since version
7.1.0, the methodmatchesof the classArgon2PasswordEncoderuses the classorg.springframework.util.StringUtils. However, this class is missing from the jar file downloaded my Maven, causing ajava.lang.NoClassDefFoundErrorto be thrown.To Reproduce
I've included an example below.
Expected behavior
The class
org.springframework.util.StringUtilsshould be packaged so that nojava.lang.NoClassDefFoundErroris thrownSample
This example was created by Google AI and slightly edited by me (the of this report was not written by AI).
Create this
pom.xmlCreate
src/main/java/App.java:Then run
mvn compile exec:java -Dexec.mainClass="App"When using version
7.1.0or7.1.1, this will error as described above, while with version7.0.7, this will succeed.