Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Add XML configuration guidance to deprecation warnings #17753

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
khj68 wants to merge 1 commit into spring-projects:main
base: main
Choose a base branch
Loading
from khj68:fix/xml-deprecation-guidance

Conversation

Copy link

@khj68 khj68 commented Aug 17, 2025

Description

This PR adds XML configuration guidance to the deprecation warnings in DefaultFilterChainValidator.

Problem

After upgrading to Spring Security 6.5.0, XML-configured applications receive deprecation warnings about authorizeRequests usage, even though they're using the officially supported XML <intercept-url> configuration. This creates confusion as XML users have no way to resolve these warnings.

Solution

Added clarifying notes to the deprecation warning messages that:

  • Inform XML users that the warning can be ignored for XML configurations
  • Clarify that XML users should continue using standard <intercept-url> elements
  • Make it clear that the deprecation only affects Java/Kotlin configuration users

Changes

  • Updated warning messages in DefaultFilterChainValidator.java to include XML-specific guidance

Testing

  • The changes are documentation-only and don't affect functionality
  • Existing tests should continue to pass

Closes gh-17259

When using XML-based Spring Security configuration, the standard
<intercept-url> elements internally translate to the deprecated
authorizeRequests mechanism, causing warnings that cannot be resolved
by XML users.
This change adds clarification to the deprecation warnings, informing
XML users that:
1. The warning can be ignored for XML configurations
2. They should continue using standard <intercept-url> elements
3. The deprecation only affects Java/Kotlin configuration users
This resolves the confusion for XML users who receive deprecation
warnings despite using officially supported XML configuration.
Closes spring-projectsgh-17259
Signed-off-by: khj68 <junthewise@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Reviewers
No reviews
Assignees
No one assigned
Labels
status: waiting-for-triage An issue we've not yet triaged
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

Deprecation warning about authorizeRequests should also contain XML guidance

AltStyle によって変換されたページ (->オリジナル) /