{"record":{"id":"2fc1011891620ea7","repo":"spring-projects/spring-security","slug":"instead-of-calling-this-setter-please-call-tobuil","errorCode":null,"errorMessage":"Instead of calling this setter, please call toBuilder to create a new instance","messagePattern":"Instead of calling this setter, please call toBuilder to create a new instance","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"core/src/main/java/org/springframework/security/core/SimpleAuthentication.java","lineNumber":79,"sourceCode":"\n\t@Override\n\tpublic @Nullable Object getDetails() {\n\t\treturn this.details;\n\t}\n\n\t@Override\n\tpublic @Nullable Object getPrincipal() {\n\t\treturn this.principal;\n\t}\n\n\t@Override\n\tpublic boolean isAuthenticated() {\n\t\treturn this.authenticated;\n\t}\n\n\t@Override\n\tpublic void setAuthenticated(boolean isAuthenticated) throws IllegalArgumentException {\n\t\tthrow new IllegalArgumentException(\n\t\t\t\t\"Instead of calling this setter, please call toBuilder to create a new instance\");\n\t}\n\n\t@Override\n\tpublic String getName() {\n\t\treturn (this.principal == null) ? \"\" : this.principal.toString();\n\t}\n\n\tstatic final class Builder implements Authentication.Builder<Builder> {\n\n\t\tprivate final Log logger = LogFactory.getLog(getClass());\n\n\t\tprivate final Collection<GrantedAuthority> authorities = new LinkedHashSet<>();\n\n\t\tprivate @Nullable Object principal;\n\n\t\tprivate @Nullable Object credentials;\n","sourceCodeStart":61,"sourceCodeEnd":97,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/core/src/main/java/org/springframework/security/core/SimpleAuthentication.java#L61-L97","documentation":"SimpleAuthentication is an immutable authentication token; its setAuthenticated method deliberately always throws IllegalArgumentException to enforce immutability. Callers must create a new instance via toBuilder() instead of mutating an existing one.","triggerScenarios":"Calling setAuthenticated(true/false) on a SimpleAuthentication instance returned by an API (e.g. an already-authenticated token from the security context).","commonSituations":"Code that historically mutated UsernamePasswordAuthenticationToken or other mutable tokens being ported to the immutable SimpleAuthentication introduced in recent Spring Security 6.x/7 refactors.","solutions":["Use toBuilder() to create a new instance with authenticated=true and store that in the SecurityContext","If you need a mutable token, use a mutable Authentication implementation such as UsernamePasswordAuthenticationToken","Refactor code that toggles authentication state to construct the token with the correct state up front"],"exampleFix":"// before\nauth.setAuthenticated(true);\n// after\nAuthentication newAuth = SimpleAuthentication.builder(auth)\n    .authenticated(true)\n    .build();","handlingStrategy":"type-guard","validationCode":"if (auth instanceof SimpleAuthentication) { /* immutable: do not call setAuthenticated */ }","typeGuard":"boolean isImmutableToken(Authentication a) { return a instanceof SimpleAuthentication; }","tryCatchPattern":null,"preventionTips":["Treat SimpleAuthentication as immutable — never call its setters","Use toBuilder() to derive a modified instance","Use mutable tokens like UsernamePasswordAuthenticationToken when mutation is required","Audit legacy code that calls setAuthenticated after migration"],"tags":["immutability","api-migration","authentication"],"backgroundTag":"deprecated-api-usage","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}