Add RuntimeHints for FactorGrantedAuthority - #19593
Open
jyx-07 wants to merge 1 commit into
Open
Conversation
FactorGrantedAuthority shipped without RuntimeHints registration, so it was missing reflection and serialization support under a GraalVM native image. This breaks callers that cache it via Java serialization, such as Spring Session Data Redis's JdkSerializationRedisSerializer, which fails with "SerializationConstructorAccessor class not found" because the constructor accessor for the class was never generated at build time. FactorGrantedAuthority carries a java.time.Instant, whose own serialized form delegates to the JDK-internal java.time.Ser proxy, so that type needs the same treatment. Register FactorGrantedAuthority, Instant, and java.time.Ser in CoreSecurityRuntimeHints using TypeHint.Builder#withJavaSerialization, alongside the other Authentication-related types it already covers for the same reason. Closes spring-projectsgh-18739 Signed-off-by: jyx-07 <s25069@gsm.hs.kr>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
FactorGrantedAuthorityshipped without anyRuntimeHintsregistration, so under a GraalVM native image it has no reflection or Java-serialization support. This breaks any caller that serializes it via plain Java serialization — for example Spring Session Data Redis'sJdkSerializationRedisSerializer— which fails with:FactorGrantedAuthoritycarries ajava.time.Instant, whose own serialized form delegates to the JDK-internaljava.time.Serproxy class, so that type needs the same treatment (referenced viaTypeReference.of("java.time.Ser")since it isn't public API).This registers reflection and Java-serialization hints for
FactorGrantedAuthority,Instant, andjava.time.Serin the existingCoreSecurityRuntimeHints, usingTypeHint.Builder#withJavaSerialization, alongside the otherAuthentication-related types it already covers for the same class of problem.Credit to @k6leung, who diagnosed the root cause and validated this exact set of hints as a workaround in #18739.
Test plan
RuntimeHintsPredicates-based tests toCoreSecurityRuntimeHintsTestsasserting reflection and Java-serialization hints are registered forFactorGrantedAuthority,Instant, andjava.time.Ser../gradlew :spring-security-core:test— full module suite passes.Closes gh-18739