Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SEC-2371: Remove ObjectPostProcessor.QUIESENT_POSTPROCESSOR #2592

spring-issuemaster opened this issue Oct 18, 2013 · 1 comment


None yet
2 participants
Copy link

commented Oct 18, 2013

Rob Winch (Migrated from SEC-2371) said:

The presence of ObjectPostProcessor.QUIESENT_POSTPROCESSOR encourages improper usage of the builders which can cause improper instantiation of objects.


This comment has been minimized.

Copy link

commented Oct 18, 2013

Rob Winch said:

Ideally users that were creating their own AuthenticationManagerBuilder should be using the global instance which Spring Security Java Configuration is aware of and will use automatically.

public void configureGlobal(AuthenticationManagerBuilder auth) {
   // ... configure it ...

If users need an AuthenticationManger instance, they can do the following:

public AuthenticationManager authenticationManager(AuthenticationManagerBuilder auth) {
   return auth
              // ... configure auth ...

Users that need to create their own AuthenticationManagerBuilder should now do so by autowiring the ObjectPostProcessor instance. An example can be seen below:

public AuthenticationManager secondAuthenticationManager(ObjectPostProcessor<Object> opp) {
    AuthenticationManagerBuilder auth = new AuthenticationManagerBuilder(opp);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.