{"record":{"id":"2d0720af9ec2f6ac","repo":"spring-projects/spring-security","slug":"authorizationmanagerfactory-must-be-an-instance-of-2d0720","errorCode":null,"errorMessage":"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory","messagePattern":"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory","errorType":"exception","errorClass":"IllegalStateException","httpStatus":null,"severity":"error","filePath":"data/src/main/java/org/springframework/security/data/repository/query/SecurityEvaluationContextExtension.java","lineNumber":185,"sourceCode":"\t * @param authorizationManagerFactory the {@link AuthorizationManagerFactory} to use.\n\t * Cannot be null.\n\t * @since 7.0\n\t */\n\tpublic void setAuthorizationManagerFactory(AuthorizationManagerFactory<Object> authorizationManagerFactory) {\n\t\tAssert.notNull(authorizationManagerFactory, \"authorizationManagerFactory cannot be null\");\n\t\tthis.authorizationManagerFactory = authorizationManagerFactory;\n\t}\n\n\t/**\n\t * Allows accessing the {@link DefaultAuthorizationManagerFactory} for getting and\n\t * setting defaults. This method will be removed in Spring Security 8.\n\t * @return the {@link DefaultAuthorizationManagerFactory}\n\t * @throws IllegalStateException if a different {@link AuthorizationManagerFactory}\n\t * was already set\n\t */\n\tprivate DefaultAuthorizationManagerFactory<Object> getDefaultAuthorizationManagerFactory() {\n\t\tif (!(this.authorizationManagerFactory instanceof DefaultAuthorizationManagerFactory<Object> defaultAuthorizationManagerFactory)) {\n\t\t\tthrow new IllegalStateException(\n\t\t\t\t\t\"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory\");\n\t\t}\n\n\t\treturn defaultAuthorizationManagerFactory;\n\t}\n\n\t/**\n\t * Sets the {@link AuthenticationTrustResolver} to be used. Default is\n\t * {@link AuthenticationTrustResolverImpl}. Cannot be null.\n\t * @param trustResolver the {@link AuthenticationTrustResolver} to use\n\t * @since 5.8\n\t * @deprecated Use\n\t * {@link #setAuthorizationManagerFactory(AuthorizationManagerFactory)} instead\n\t */\n\t@Deprecated(since = \"7.0\")\n\tpublic void setTrustResolver(AuthenticationTrustResolver trustResolver) {\n\t\tAssert.notNull(trustResolver, \"trustResolver cannot be null\");\n\t\tgetDefaultAuthorizationManagerFactory().setTrustResolver(trustResolver);","sourceCodeStart":167,"sourceCodeEnd":203,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/data/src/main/java/org/springframework/security/data/repository/query/SecurityEvaluationContextExtension.java#L167-L203","documentation":"SecurityEvaluationContextExtension allows customizing a role hierarchy/trust resolver by mutating its AuthorizationManagerFactory, but those mutators only work with the default implementation. When a custom AuthorizationManagerFactory was set, getDefaultAuthorizationManagerFactory throws IllegalStateException because it cannot safely apply the customization to an unknown implementation.","triggerScenarios":"Setting a custom AuthorizationManagerFactory on SecurityEvaluationContextExtension, then calling setTrustResolver, setRoleHierarchy, or setDefaultRolePrefix.","commonSituations":"Spring Data + SpEL security setups where teams plug in a custom factory for role prefix handling and then also try to set a role hierarchy; combining beans from different configuration profiles.","solutions":["Remove the custom AuthorizationManagerFactory and keep the DefaultAuthorizationManagerFactory so the setters can be used.","Apply the role hierarchy / trust resolver customization directly inside your custom factory implementation instead of via the setters.","If both are needed, subclass or reconfigure so one mechanism owns the customization."],"exampleFix":"// before\nextension.setAuthorizationManagerFactory(customFactory);\nextension.setRoleHierarchy(roleHierarchy); // throws\n// after\nSecurityEvaluationContextExtension extension = new SecurityEvaluationContextExtension();\nextension.setRoleHierarchy(roleHierarchy); // default factory kept","handlingStrategy":"try-catch","validationCode":"if (extension.getAuthorizationManagerFactory() != null\n        && !(extension.getAuthorizationManagerFactory() instanceof DefaultAuthorizationManagerFactory)) {\n    // customization setters unsupported: apply them inside the custom factory instead\n}","typeGuard":null,"tryCatchPattern":"try {\n    extension.setRoleHierarchy(roleHierarchy);\n} catch (IllegalStateException e) {\n    log.warn(\"Custom AuthorizationManagerFactory in use; apply role hierarchy there\", e);\n}","preventionTips":["Don't mix a custom AuthorizationManagerFactory with the setter-based customization.","Centralize role-hierarchy config in one bean.","Document the mutually exclusive config options for the team."],"tags":["java","spring-security","spring-data","authorization","illegal-state"],"backgroundTag":"conflicting-config-options","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}