{"record":{"id":"4373c00153449f72","repo":"spring-projects/spring-security","slug":"the-request-was-rejected-because-the-http-method-4373c0","errorCode":null,"errorMessage":"The request was rejected because the HTTP method \"<method>\" was not included within the list of allowed HTTP methods <allowedHttpMethods>","messagePattern":"The request was rejected because the HTTP method \"<method>\" was not included within the list of allowed HTTP methods <allowedHttpMethods>","errorType":"exception","errorClass":"ServerExchangeRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java","lineNumber":577,"sourceCode":"\n\tprivate void urlBlocklistsRemoveAll(Collection<String> values) {\n\t\tthis.encodedUrlBlocklist.removeAll(values);\n\t\tthis.decodedUrlBlocklist.removeAll(values);\n\t}\n\n\tprivate void rejectNonPrintableAsciiCharactersInFieldName(String toCheck, String propertyName) {\n\t\tif (!containsOnlyPrintableAsciiCharacters(toCheck)) {\n\t\t\tthrow new ServerExchangeRejectedException(String\n\t\t\t\t.format(\"The %s was rejected because it can only contain printable ASCII characters.\", propertyName));\n\t\t}\n\t}\n\n\tprivate void rejectForbiddenHttpMethod(ServerHttpRequest request) {\n\t\tif (this.allowedHttpMethods == ALLOW_ANY_HTTP_METHOD) {\n\t\t\treturn;\n\t\t}\n\t\tif (!this.allowedHttpMethods.contains(request.getMethod())) {\n\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\"The request was rejected because the HTTP method \\\"\" + request.getMethod()\n\t\t\t\t\t\t\t+ \"\\\" was not included within the list of allowed HTTP methods \" + this.allowedHttpMethods);\n\t\t}\n\t}\n\n\tprivate void rejectedBlocklistedUrls(ServerHttpRequest request) {\n\t\tfor (String forbidden : this.encodedUrlBlocklist) {\n\t\t\tif (encodedUrlContains(request, forbidden)) {\n\t\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the URL contained a potentially malicious String \\\"\"\n\t\t\t\t\t\t\t\t+ forbidden + \"\\\"\");\n\t\t\t}\n\t\t}\n\t\tfor (String forbidden : this.decodedUrlBlocklist) {\n\t\t\tif (decodedUrlContains(request, forbidden)) {\n\t\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the URL contained a potentially malicious String \\\"\"\n\t\t\t\t\t\t\t\t+ forbidden + \"\\\"\");","sourceCodeStart":559,"sourceCodeEnd":595,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java#L559-L595","documentation":"StrictServerWebExchangeFirewall restricts requests to a configured set of allowed HTTP methods. rejectForbiddenHttpMethod throws ServerExchangeRejectedException when the request method is not in allowedHttpMethods (unless configured to allow any method). This is an opt-in hardening: by default all methods are permitted, so this only fires after explicit configuration.","triggerScenarios":"The firewall bean was configured with setAllowedHttpMethods(Set<HttpMethod>) that omits a method the client uses (e.g. OPTIONS for CORS preflight, PATCH, or HEAD), so any request with that method is rejected during getFirewalledExchange.","commonSituations":"Hardening configuration forgetting OPTIONS, breaking CORS preflight; health-check probes using HEAD while only GET is allowed; API evolution adding PATCH/DELETE after the allowlist was fixed; load balancers issuing OPTIONS pings.","solutions":["Add the missing method to the allowlist: firewall.setAllowedHttpMethods(new HashSet<>(List.of(GET, POST, PUT, DELETE, OPTIONS))).","Add OPTIONS specifically to fix CORS preflight failures.","If no restriction is desired, call setAllowedHttpMethods(ALLOW_ANY_HTTP_METHOD) to restore default behavior.","Check client/probe method usage (health checks, preflight) and align the allowlist with what is genuinely used."],"exampleFix":"// before\nStrictServerWebExchangeFirewall firewall = new StrictServerWebExchangeFirewall();\nfirewall.setAllowedHttpMethods(Set.of(HttpMethod.GET, HttpMethod.POST));\n// after\nfirewall.setAllowedHttpMethods(new HashSet<>(Arrays.asList(\n    HttpMethod.GET, HttpMethod.POST, HttpMethod.PUT, HttpMethod.DELETE, HttpMethod.OPTIONS)));","handlingStrategy":"validation","validationCode":"// Pre-flight check against the configured allowlist\nSet<HttpMethod> allowed = firewall.getAllowedHttpMethods();\nif (allowed != ALLOW_ANY_HTTP_METHOD && !allowed.contains(HttpMethod.valueOf(method))) {\n    throw new IllegalArgumentException(\"Method not allowed by firewall: \" + method);\n}","typeGuard":null,"tryCatchPattern":"@ExceptionHandler(ServerExchangeRejectedException.class)\nResponseEntity<Void> handle(ServerExchangeRejectedException e) {\n    log.warn(\"Rejected method: {}\", e.getMessage());\n    return ResponseEntity.status(HttpStatus.METHOD_NOT_ALLOWED).build();\n}","preventionTips":["Always include OPTIONS in the allowlist for CORS preflight","Include HEAD for health-check probes","Keep the allowlist in config reviewed alongside API changes","Use ALLOW_ANY_HTTP_METHOD unless restriction is required"],"tags":["spring-security","webflux","firewall","http-method","request-rejected"],"backgroundTag":"unsupported-operation","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}