{"record":{"id":"4502a62f9058e9c0","repo":"spring-projects/spring-security","slug":"no-visible-webinvocationprivilegeevaluator-instanc","errorCode":null,"errorMessage":"No visible WebInvocationPrivilegeEvaluator instance could be found in the application context. There must be at least one in order to support the use of URL access checks in 'authorize' tags.","messagePattern":"No visible WebInvocationPrivilegeEvaluator instance could be found in the application context\\. There must be at least one in order to support the use of URL access checks in 'authorize' tags\\.","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"error","filePath":"taglibs/src/main/java/org/springframework/security/taglibs/authz/AbstractAuthorizeTag.java","lineNumber":219,"sourceCode":"\t\t\tif (FilterInvocation.class\n\t\t\t\t.equals(GenericTypeResolver.resolveTypeArgument(handler.getClass(), SecurityExpressionHandler.class))) {\n\t\t\t\treturn handler;\n\t\t\t}\n\t\t}\n\t\tthrow new IOException(\"No visible WebSecurityExpressionHandler instance could be found in the application \"\n\t\t\t\t+ \"context. There must be at least one in order to support expressions in JSP 'authorize' tags.\");\n\t}\n\n\tprivate WebInvocationPrivilegeEvaluator getPrivilegeEvaluator() throws IOException {\n\t\tWebInvocationPrivilegeEvaluator privEvaluatorFromRequest = (WebInvocationPrivilegeEvaluator) getRequest()\n\t\t\t.getAttribute(WebAttributes.WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE);\n\t\tif (privEvaluatorFromRequest != null) {\n\t\t\treturn privEvaluatorFromRequest;\n\t\t}\n\t\tApplicationContext ctx = getApplicationContext();\n\t\tMap<String, WebInvocationPrivilegeEvaluator> wipes = ctx.getBeansOfType(WebInvocationPrivilegeEvaluator.class);\n\t\tif (wipes.isEmpty()) {\n\t\t\tthrow new IOException(\n\t\t\t\t\t\"No visible WebInvocationPrivilegeEvaluator instance could be found in the application \"\n\t\t\t\t\t\t\t+ \"context. There must be at least one in order to support the use of URL access checks in 'authorize' tags.\");\n\t\t}\n\t\treturn (WebInvocationPrivilegeEvaluator) wipes.values().toArray()[0];\n\t}\n\n\tprivate ApplicationContext getApplicationContext() {\n\t\tObject value = getRequest().getAttribute(WebAttributes.APPLICATION_CONTEXT_ATTRIBUTE);\n\t\tif (value == null) {\n\t\t\treturn SecurityWebApplicationContextUtils.findRequiredWebApplicationContext(getServletContext());\n\t\t}\n\t\tif (value instanceof ApplicationContext context) {\n\t\t\treturn context;\n\t\t}\n\t\tthrow new IllegalArgumentException(\"WebAttributes.APPLICATION_CONTEXT_ATTRIBUTE value must be of type \"\n\t\t\t\t+ \"ApplicationContext, found type \" + value.getClass());\n\t}\n","sourceCodeStart":201,"sourceCodeEnd":237,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/taglibs/src/main/java/org/springframework/security/taglibs/authz/AbstractAuthorizeTag.java#L201-L237","documentation":"The url attribute of the JSP 'authorize' tag needs a WebInvocationPrivilegeEvaluator to check whether the current user can access a URL. AbstractAuthorizeTag.getPrivilegeEvaluator() first checks a request attribute, then the ApplicationContext; if no WebInvocationPrivilegeEvaluator beans exist it throws this IOException.","triggerScenarios":"Using <sec:authorize url=\"/some/path\"> (authorizeUsingUrlCheck) when ctx.getBeansOfType(WebInvocationPrivilegeEvaluator.class) is empty and no request attribute WebAttributes.WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE is set.","commonSituations":"Security configured only for method security (no FilterSecurityInterceptor/AuthorizationFilter, so no privilege evaluator bean is registered); using the tag without a security filter chain; older/newer Spring Security version mismatch where the WIP bean isn't auto-exposed; testing tags outside a full web setup.","solutions":["Configure HTTP-based Spring Security (SecurityFilterChain with authorizeHttpRequests) so a WebInvocationPrivilegeEvaluator bean is registered in the context.","Pre-populate the request attribute WebAttributes.WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE if you manage evaluators manually.","Ensure the tag's ApplicationContext is the one containing the Security beans (context hierarchy/parent lookup).","Replace the url attribute with an access expression (which uses the expression handler path) or move the check to Java authorization APIs.","Verify spring-security-web/taglibs versions match so the privilege evaluator is auto-published."],"exampleFix":"<!-- before -->\n<sec:authorize url=\"/admin/**\">...</sec:authorize>\n<!-- with no security filter chain configured -->\n\n<!-- after: ensure HTTP security is configured, or use access expression -->\n<sec:authorize access=\"hasRole('ADMIN')\">...</sec:authorize>","handlingStrategy":"try-catch","validationCode":"Map<String, WebInvocationPrivilegeEvaluator> wipes = ctx.getBeansOfType(WebInvocationPrivilegeEvaluator.class);\nif (wipes.isEmpty()) {\n    throw new IllegalStateException(\"No WebInvocationPrivilegeEvaluator bean; configure HTTP security with authorizeHttpRequests\");\n}","typeGuard":null,"tryCatchPattern":"try { ... tag evaluation ... } catch (IOException ex) { if (ex.getMessage().contains(\"WebInvocationPrivilegeEvaluator\")) { log.error(\"URL-based authorize tag requires an HTTP security configuration\"); } throw ex; }","preventionTips":["Prefer access expressions over the url attribute when only method security is configured","Ensure a SecurityFilterChain with authorizeHttpRequests exists to publish the privilege evaluator","Set WebAttributes.WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE when managing evaluators manually"],"tags":["jsp","taglibs","spring-security","authorization","url-check","missing-bean"],"backgroundTag":"missing-dependency","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}