{"record":{"id":"4e49b1290b2d537d","repo":"spring-projects/spring-security","slug":"user-withdefaultpasswordencoder-is-considered-un","errorCode":null,"errorMessage":"User.withDefaultPasswordEncoder() is considered unsafe for production and is only intended for sample applications.","messagePattern":"User\\.withDefaultPasswordEncoder\\(\\) is considered unsafe for production and is only intended for sample applications\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"core/src/main/java/org/springframework/security/core/userdetails/User.java","lineNumber":283,"sourceCode":"\t *\n\t * <pre>\n\t * <code>\n\t * UserDetails user = User.withUsername(\"user\")\n\t *     .password(\"{bcrypt}$2a$10$dXJ3SW6G7P50lGmMkkmwe.20cQQubK3.HZWzG3YB1tlRy.fqvM/BG\")\n\t *     .roles(\"USER\")\n\t *     .build();\n\t * </code> </pre>\n\t * @return a UserBuilder that automatically encodes the password with the default\n\t * PasswordEncoder\n\t * @deprecated Using this method is not considered safe for production, but is\n\t * acceptable for demos and getting started. For production purposes, ensure the\n\t * password is encoded externally. See the method Javadoc for additional details.\n\t * There are no plans to remove this support. It is deprecated to indicate that this\n\t * is considered insecure for production purposes.\n\t */\n\t@Deprecated\n\tpublic static UserBuilder withDefaultPasswordEncoder() {\n\t\tlogger.warn(\"User.withDefaultPasswordEncoder() is considered unsafe for production \"\n\t\t\t\t+ \"and is only intended for sample applications.\");\n\t\tPasswordEncoder encoder = PasswordEncoderFactories.createDelegatingPasswordEncoder();\n\t\treturn builder().passwordEncoder(encoder::encode);\n\t}\n\n\tpublic static UserBuilder withUserDetails(UserDetails userDetails) {\n\t\t// @formatter:off\n\t\tUserBuilder result = withUsername(userDetails.getUsername())\n\t\t\t\t.accountExpired(!userDetails.isAccountNonExpired())\n\t\t\t\t.accountLocked(!userDetails.isAccountNonLocked())\n\t\t\t\t.authorities(userDetails.getAuthorities())\n\t\t\t\t.credentialsExpired(!userDetails.isCredentialsNonExpired())\n\t\t\t\t.disabled(!userDetails.isEnabled());\n\t\t// @formatter:on\n\t\tif (userDetails.getPassword() != null) {\n\t\t\tresult.password(userDetails.getPassword());\n\t\t}\n\t\treturn result;","sourceCodeStart":265,"sourceCodeEnd":301,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/core/src/main/java/org/springframework/security/core/userdetails/User.java#L265-L301","documentation":"User.withDefaultPasswordEncoder() is a deprecated convenience factory that builds a User with a delegating password encoder. Because a plain-text default password encoding is insecure, calling it logs this warning; it is intended only for demos and samples.","triggerScenarios":"Any invocation of User.withDefaultPasswordEncoder(), typically in test/demo code such as User.withDefaultPasswordEncoder().username(\"user\").password(\"pass\").roles(\"USER\").build().","commonSituations":"Copy-pasted sample configs copied into production; tutorials using the convenience builder; quick local prototypes.","solutions":["Use User.withUsername(...).password(encoder.encode(rawPassword)) with an explicitly configured PasswordEncoder (e.g. BCryptPasswordEncoder or DelegatingPasswordEncoder)","Use PasswordEncoderFactories.createDelegatingPasswordEncoder() and store {bcrypt}-prefixed hashes","Keep withDefaultPasswordEncoder only in non-production sample code"],"exampleFix":"// before\nUser user = User.withDefaultPasswordEncoder()\n    .username(\"user\").password(\"password\").roles(\"USER\").build();\n// after\nPasswordEncoder encoder = PasswordEncoderFactories.createDelegatingPasswordEncoder();\nUser user = User.withUsername(\"user\")\n    .password(encoder.encode(\"password\")).roles(\"USER\").build();","handlingStrategy":"validation","validationCode":"// Reject the insecure builder in your own code via an ArchUnit/checkstyle rule or review gate\nif (stackContains(\"withDefaultPasswordEncoder\")) {\n  throw new IllegalStateException(\"User.withDefaultPasswordEncoder() is not allowed in production code\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always inject and use a PasswordEncoder for user construction","Store only encoded, salted hashes ({bcrypt}...) never raw passwords","Add static analysis or code-review rules banning withDefaultPasswordEncoder outside samples"],"tags":["spring-security","deprecated-api-usage","password-encoding","insecure-default"],"backgroundTag":"deprecated-api-usage","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}