{"record":{"id":"7c5505acdb9efd93","repo":"spring-projects/spring-security","slug":"unable-to-resolve-the-client-registration-identifi","errorCode":null,"errorMessage":"Unable to resolve the Client Registration Identifier. It must be provided via @RegisteredOAuth2AuthorizedClient(\"client1\") or @RegisteredOAuth2AuthorizedClient(registrationId = \"client1\").","messagePattern":"Unable to resolve the Client Registration Identifier\\. It must be provided via @RegisteredOAuth2AuthorizedClient\\(\"client1\"\\) or @RegisteredOAuth2AuthorizedClient\\(registrationId = \"client1\"\\)\\.","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/method/annotation/OAuth2AuthorizedClientArgumentResolver.java","lineNumber":113,"sourceCode":"\t\tAssert.notNull(clientRegistrationRepository, \"clientRegistrationRepository cannot be null\");\n\t\tAssert.notNull(authorizedClientRepository, \"authorizedClientRepository cannot be null\");\n\t\tthis.authorizedClientManager = new DefaultOAuth2AuthorizedClientManager(clientRegistrationRepository,\n\t\t\t\tauthorizedClientRepository);\n\t}\n\n\t@Override\n\tpublic boolean supportsParameter(MethodParameter parameter) {\n\t\tClass<?> parameterType = parameter.getParameterType();\n\t\treturn (OAuth2AuthorizedClient.class.isAssignableFrom(parameterType) && (AnnotatedElementUtils\n\t\t\t.findMergedAnnotation(parameter.getParameter(), RegisteredOAuth2AuthorizedClient.class) != null));\n\t}\n\n\t@Override\n\tpublic @Nullable Object resolveArgument(MethodParameter parameter, @Nullable ModelAndViewContainer mavContainer,\n\t\t\tNativeWebRequest webRequest, @Nullable WebDataBinderFactory binderFactory) {\n\t\tString clientRegistrationId = this.resolveClientRegistrationId(parameter);\n\t\tif (!StringUtils.hasLength(clientRegistrationId)) {\n\t\t\tthrow new IllegalArgumentException(\"Unable to resolve the Client Registration Identifier. \"\n\t\t\t\t\t+ \"It must be provided via @RegisteredOAuth2AuthorizedClient(\\\"client1\\\") or \"\n\t\t\t\t\t+ \"@RegisteredOAuth2AuthorizedClient(registrationId = \\\"client1\\\").\");\n\t\t}\n\t\tAuthentication principal = this.securityContextHolderStrategy.getContext().getAuthentication();\n\t\tif (principal == null) {\n\t\t\tprincipal = ANONYMOUS_AUTHENTICATION;\n\t\t}\n\t\tHttpServletRequest servletRequest = webRequest.getNativeRequest(HttpServletRequest.class);\n\t\tHttpServletResponse servletResponse = webRequest.getNativeResponse(HttpServletResponse.class);\n\t\tAssert.notNull(servletRequest, \"HttpServletRequest is required for OAuth2 authorized client resolution\");\n\t\tAssert.notNull(servletResponse, \"HttpServletResponse is required for OAuth2 authorized client resolution\");\n\t\t// @formatter:off\n\t\tOAuth2AuthorizeRequest authorizeRequest = OAuth2AuthorizeRequest\n\t\t\t\t.withClientRegistrationId(clientRegistrationId)\n\t\t\t\t.principal(principal)\n\t\t\t\t.attribute(HttpServletRequest.class.getName(), servletRequest)\n\t\t\t\t.attribute(HttpServletResponse.class.getName(), servletResponse)\n\t\t\t\t.build();","sourceCodeStart":95,"sourceCodeEnd":131,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/method/annotation/OAuth2AuthorizedClientArgumentResolver.java#L95-L131","documentation":"@RegisteredOAuth2AuthorizedClient argument resolution requires an explicit registration id (value or registrationId attribute) or enough context (e.g. a current client via @CurrentOAuth2Client or default client registration). resolveArgument throws IllegalArgumentException when resolveClientRegistrationId returns empty.","triggerScenarios":"A controller method declares @RegisteredOAuth2AuthorizedClient without value/registrationId and no default or context-based registration can be inferred.","commonSituations":"Copy-pasted annotations with the placeholder stripped; refactor removing the annotation attribute; using the resolver without a setDefaultClientRegistrationId in a multi-client setup.","solutions":["Pass the registration id explicitly: @RegisteredOAuth2AuthorizedClient(\"client1\")","Configure a default via OAuth2AuthorizedClientArgumentResolver.setDefaultClientRegistrationId or @RegisteredOAuth2AuthorizedClient(registrationId=\"client1\")","Ensure a single ClientRegistration exists or set the default when only one client is configured and you rely on inference"],"exampleFix":"// before\npublic String index(@RegisteredOAuth2AuthorizedClient OAuth2AuthorizedClient client)\n// after\npublic String index(@RegisteredOAuth2AuthorizedClient(\"client1\") OAuth2AuthorizedClient client)","handlingStrategy":"validation","validationCode":"String registrationId = authorizedClient.value();\nAssert.hasText(registrationId, \"@RegisteredOAuth2AuthorizedClient requires an explicit registrationId\");","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always pass the registration id explicitly to @RegisteredOAuth2AuthorizedClient","Set a default client registration id on the resolver when using a single client","Check annotation attributes after refactors"],"tags":["spring-security","oauth2","annotation","argument-resolution"],"backgroundTag":"missing-required-argument","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}