{"record":{"id":"751752479df17ddf","repo":"spring-projects/spring-security","slug":"cannot-perform-login-for-username-already-auth","errorCode":null,"errorMessage":"Cannot perform login for '<username>' already authenticated as '<remoteUser>'","messagePattern":"Cannot perform login for '<username>' already authenticated as '<remoteUser>'","errorType":"exception","errorClass":"ServletException","httpStatus":null,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/servletapi/HttpServlet3RequestFactory.java","lineNumber":237,"sourceCode":"\t\tpublic boolean authenticate(HttpServletResponse response) throws IOException, ServletException {\n\t\t\tAuthenticationEntryPoint entryPoint = HttpServlet3RequestFactory.this.authenticationEntryPoint;\n\t\t\tif (entryPoint == null) {\n\t\t\t\tHttpServlet3RequestFactory.this.logger.debug(\n\t\t\t\t\t\t\"authenticationEntryPoint is null, so allowing original HttpServletRequest to handle authenticate\");\n\t\t\t\treturn super.authenticate(response);\n\t\t\t}\n\t\t\tif (isAuthenticated()) {\n\t\t\t\treturn true;\n\t\t\t}\n\t\t\tentryPoint.commence(this, response,\n\t\t\t\t\tnew AuthenticationCredentialsNotFoundException(\"User is not Authenticated\"));\n\t\t\treturn false;\n\t\t}\n\n\t\t@Override\n\t\tpublic void login(String username, String password) throws ServletException {\n\t\t\tif (isAuthenticated()) {\n\t\t\t\tthrow new ServletException(\"Cannot perform login for '\" + username + \"' already authenticated as '\"\n\t\t\t\t\t\t+ getRemoteUser() + \"'\");\n\t\t\t}\n\t\t\tAuthenticationManager authManager = HttpServlet3RequestFactory.this.authenticationManager;\n\t\t\tif (authManager == null) {\n\t\t\t\tHttpServlet3RequestFactory.this.logger\n\t\t\t\t\t.debug(\"authenticationManager is null, so allowing original HttpServletRequest to handle login\");\n\t\t\t\tsuper.login(username, password);\n\t\t\t\treturn;\n\t\t\t}\n\t\t\tAuthentication authentication = getAuthentication(authManager, username, password);\n\t\t\tSecurityContext context = HttpServlet3RequestFactory.this.securityContextHolderStrategy\n\t\t\t\t.createEmptyContext();\n\t\t\tcontext.setAuthentication(authentication);\n\t\t\tHttpServlet3RequestFactory.this.securityContextHolderStrategy.setContext(context);\n\t\t\tHttpServlet3RequestFactory.this.securityContextRepository.saveContext(context, this, this.response);\n\t\t}\n\n\t\tprivate Authentication getAuthentication(AuthenticationManager authManager, String username, String password)","sourceCodeStart":219,"sourceCodeEnd":255,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/servletapi/HttpServlet3RequestFactory.java#L219-L255","documentation":"Servlet 3.0 API login(username, password) on the request wrapper refuses to run when the current request is already authenticated. Performing a new programmatic login while an identity is established would silently replace the user, so Spring Security throws ServletException naming both the requested username and the current remote user.","triggerScenarios":"Calling request.login(username, password) via the HttpServletRequest wrapper created by HttpServlet3RequestFactory when isAuthenticated() is true — i.e. a user is already logged in on this request/session.","commonSituations":"Re-submitting a login form inside an already-authenticated session; double-invoking login logic (e.g. filter plus controller both call login); session reuse after SSO/auto-login already authenticated the request.","solutions":["Check request.getRemoteUser()/isAuthenticated() before calling login and skip if already authenticated","Invalidate the session and clear authentication before performing a fresh login","Route the flow through a dedicated login endpoint that runs unauthenticated only","Handle ServletException and treat 'already authenticated' as a no-op or redirect"],"exampleFix":"// before\nrequest.login(username, password);\n// after\nif (request.getRemoteUser() == null) {\n    request.login(username, password);\n}","handlingStrategy":"type-guard","validationCode":"// guard before calling login\nif (request.getRemoteUser() != null || request.getUserPrincipal() != null) {\n    return; // already authenticated, skip login\n}","typeGuard":"function canLogin(HttpServletRequest request) {\n    return request.getRemoteUser() == null && request.getUserPrincipal() == null;\n}","tryCatchPattern":"try {\n    request.login(username, password);\n} catch (ServletException ex) {\n    if (ex.getMessage().startsWith(\"Cannot perform login for\")) {\n        // already authenticated: redirect or no-op\n    }\n}","preventionTips":["Only expose login flows on unauthenticated routes","Check isAuthenticated()/getRemoteUser() before programmatic login","Avoid calling login from multiple layers (filter + controller) for the same request"],"tags":["spring-security","servlet-api","authentication"],"backgroundTag":"invalid-state-transition","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}