{"record":{"id":"25d1dccb6a50c0bf","repo":"spring-projects/spring-security","slug":"authorizationmanagerfactory-must-be-an-instance-of","errorCode":null,"errorMessage":"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory","messagePattern":"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory","errorType":"exception","errorClass":"IllegalStateException","httpStatus":null,"severity":"error","filePath":"core/src/main/java/org/springframework/security/access/expression/AbstractSecurityExpressionHandler.java","lineNumber":140,"sourceCode":"\t}\n\n\tprotected final AuthorizationManagerFactory<T> getAuthorizationManagerFactory() {\n\t\treturn this.authorizationManagerFactory;\n\t}\n\n\t/**\n\t * Allows accessing the {@link DefaultAuthorizationManagerFactory} for getting and\n\t * setting defaults. This method will be removed in Spring Security 8.\n\t * @return the {@link DefaultAuthorizationManagerFactory}\n\t * @throws IllegalStateException if a different {@link AuthorizationManagerFactory}\n\t * was already set\n\t * @deprecated Use\n\t * {@link #setAuthorizationManagerFactory(AuthorizationManagerFactory)} instead\n\t */\n\t@Deprecated(since = \"7.0\")\n\tprotected final DefaultAuthorizationManagerFactory<T> getDefaultAuthorizationManagerFactory() {\n\t\tif (!(this.authorizationManagerFactory instanceof DefaultAuthorizationManagerFactory<T> defaultAuthorizationManagerFactory)) {\n\t\t\tthrow new IllegalStateException(\n\t\t\t\t\t\"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory\");\n\t\t}\n\n\t\treturn defaultAuthorizationManagerFactory;\n\t}\n\n\t/**\n\t * Returns the {@link RoleHierarchy} to use.\n\t * @deprecated Use {@link #getDefaultAuthorizationManagerFactory()} instead\n\t */\n\t@Deprecated(since = \"7.0\")\n\tprotected @Nullable RoleHierarchy getRoleHierarchy() {\n\t\treturn this.roleHierarchy;\n\t}\n\n\t/**\n\t * Sets the {@link RoleHierarchy} to use.\n\t * @deprecated Use","sourceCodeStart":122,"sourceCodeEnd":158,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/core/src/main/java/org/springframework/security/access/expression/AbstractSecurityExpressionHandler.java#L122-L158","documentation":"AbstractSecurityExpressionHandler's deprecated getDefaultAuthorizationManagerFactory() assumes the configured AuthorizationManagerFactory is the default implementation. If a custom AuthorizationManagerFactory was set (setAuthorizationManagerFactory) that is not a DefaultAuthorizationManagerFactory, this deprecated accessor throws IllegalStateException.","triggerScenarios":"Calling getDefaultAuthorizationManagerFactory() (directly or via setRoleHierarchy wiring that relies on it) after having installed a custom AuthorizationManagerFactory implementation via setAuthorizationManagerFactory.","commonSituations":"Legacy code (pre-7.0 style) customizing role hierarchy while newer code on the same handler swapped in a non-default AuthorizationManagerFactory; migrating to Spring Security 7 with mixed legacy and new APIs.","solutions":["Stop using the deprecated getDefaultAuthorizationManagerFactory(); configure the role hierarchy via the AuthorizationManagerFactory or on the expression handler directly","Either remove the custom AuthorizationManagerFactory so the default is used, or make the custom factory extend DefaultAuthorizationManagerFactory","Refactor callers (e.g. custom setRoleHierarchy overrides) to the new AuthorizationManagerFactory-based API"],"exampleFix":"// before\nhandler.setAuthorizationManagerFactory(new CustomAuthorizationManagerFactory<>());\nDefaultAuthorizationManagerFactory<T> amf = handler.getDefaultAuthorizationManagerFactory(); // throws\n\n// after\nhandler.setRoleHierarchy(new RoleHierarchyImpl(\"ROLE_A > ROLE_B\")); // use non-deprecated API, avoid the deprecated accessor","handlingStrategy":"type-guard","validationCode":"if (!(handler instanceof AbstractSecurityExpressionHandler<?> aseh)\n    || !(isDefaultAuthorizationManagerFactory(aseh))) {\n  // use the new AuthorizationManagerFactory API instead\n}","typeGuard":"boolean isDefaultAuthorizationManagerFactory(AbstractSecurityExpressionHandler<?> h) {\n  try {\n    java.lang.reflect.Field f = AbstractSecurityExpressionHandler.class.getDeclaredField(\"authorizationManagerFactory\");\n    f.setAccessible(true);\n    return f.get(h) instanceof DefaultAuthorizationManagerFactory;\n  } catch (ReflectiveOperationException e) {\n    return false;\n  }\n}","tryCatchPattern":"try {\n  DefaultAuthorizationManagerFactory<T> amf = handler.getDefaultAuthorizationManagerFactory();\n} catch (IllegalStateException e) {\n  // custom AuthorizationManagerFactory in use; migrate to setAuthorizationManagerFactory API\n}","preventionTips":["Avoid the @Deprecated getDefaultAuthorizationManagerFactory accessor after Spring Security 7","Only call it when you know the default factory was not replaced","Keep role hierarchy and authorization manager customization on one consistent API surface"],"tags":["spring-security","authorization","deprecated-api","illegal-state"],"backgroundTag":"deprecated-api-usage","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}