Skip to content

Add defaultAuthenticationEntryPointFor to Reactive ExceptionHandlingSpec - #19800

Open
ZaMan0806 wants to merge 1 commit into
spring-projects:mainfrom
ZaMan0806:gh-9663
Open

ZaMan0806 wants to merge 1 commit into
spring-projects:mainfrom
ZaMan0806:gh-9663

Conversation

@ZaMan0806

Copy link
Copy Markdown

This PR adds ServerHttpSecurity.ExceptionHandlingSpec#defaultAuthenticationEntryPointFor(ServerAuthenticationEntryPoint, ServerWebExchangeMatcher), aligning it with ExceptionHandlingConfigurer#defaultAuthenticationEntryPointFor on the servlet side. It also adds the equivalent to ServerExceptionHandlingDsl for the Kotlin DSL.

Closes gh-9663

Ordering

Built-in features register their defaults in ServerHttpSecurity#defaultEntryPoints at build time, and formLogin inserts its entry at index 0. If user-registered entries were simply appended to that list, formLogin's HTML matcher would take precedence over them. To keep user-registered entries in charge, which matches the servlet behavior where they are registered before the built-in ones, the spec keeps its own list, and that list is consulted first. When nothing matches, the fallback stays the same as today (the last default).

requestWhenDefaultAuthenticationEntryPointForAndFormLoginThenPreferredEntryPointTakesPrecedence covers this case. I confirmed that it fails if the entries are appended directly to defaultEntryPoints.

An explicitly configured authenticationEntryPoint(...) still overrides all defaults, and nothing changes when defaultAuthenticationEntryPointFor is not used.

I'm happy to adjust the ordering if a different behavior is preferred.

Tests

  • ExceptionHandlingSpecTests: matching and non-matching requests, precedence over formLogin, explicit authenticationEntryPoint override, and null argument checks
  • ServerExceptionHandlingDslTests: Kotlin DSL support

This aligns ServerHttpSecurity.ExceptionHandlingSpec with the servlet
ExceptionHandlingConfigurer by allowing a ServerAuthenticationEntryPoint
to be registered for a given ServerWebExchangeMatcher.

Entry points registered this way are consulted before the defaults
contributed by features like formLogin and httpBasic.

Closes spring-projectsgh-9663

Signed-off-by: zaman <roblery128@gmail.com>
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add ExceptionHandlingSpec.defaultAuthenticationEntryPointFor()

2 participants