{"record":{"id":"7e96045bee51b7c5","repo":"spring-projects/spring-security","slug":"denying-user-s-permission-s-on-object-s","errorCode":null,"errorMessage":"Denying user %s permission '%s' on object %s","messagePattern":"Denying user (.+?) permission '(.+?)' on object (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"core/src/main/java/org/springframework/security/access/expression/DenyAllPermissionEvaluator.java","lineNumber":46,"sourceCode":"\n/**\n * A null PermissionEvaluator which denies all access. Used by default for situations when\n * permission evaluation should not be required.\n *\n * @author Luke Taylor\n * @since 3.0\n */\npublic class DenyAllPermissionEvaluator implements PermissionEvaluator {\n\n\tprivate final Log logger = LogFactory.getLog(getClass());\n\n\t/**\n\t * Always denies permission.\n\t * @return false always\n\t */\n\t@Override\n\tpublic boolean hasPermission(Authentication authentication, @Nullable Object target, Object permission) {\n\t\tthis.logger.warn(LogMessage.format(\"Denying user %s permission '%s' on object %s\", authentication.getName(),\n\t\t\t\tpermission, target));\n\t\treturn false;\n\t}\n\n\t/**\n\t * Always denies permission.\n\t * @return false always\n\t */\n\t@Override\n\tpublic boolean hasPermission(Authentication authentication, Serializable targetId, String targetType,\n\t\t\tObject permission) {\n\t\tthis.logger.warn(LogMessage.format(\"Denying user %s permission '%s' on object with Id %s\",\n\t\t\t\tauthentication.getName(), permission, targetId));\n\t\treturn false;\n\t}\n\n}\n","sourceCodeStart":28,"sourceCodeEnd":64,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/core/src/main/java/org/springframework/security/access/expression/DenyAllPermissionEvaluator.java#L28-L64","documentation":"DenyAllPermissionEvaluator is a fail-closed PermissionEvaluator that always returns false for hasPermission(authentication, target, permission), logging who and what was denied. It exists so that SpEL @PreAuthorize(\"hasPermission(...)\" expressions fail safe when no real evaluator is registered.","triggerScenarios":"A method-security or SpEL expression calls hasPermission('#target', 'permission') while the only registered PermissionEvaluator is DenyAllPermissionEvaluator (the default when none is configured).","commonSituations":"Developers using hasPermission() in @PreAuthorize/@PostAuthorize without registering a custom PermissionEvaluator; bean named permissionEvaluator missing from the context.","solutions":["Implement a custom PermissionEvaluator and register it via .expressionHandler() / a DefaultMethodSecurityExpressionHandler with your evaluator set","If SpEL hasPermission is not intended, replace expressions with role/authority checks like hasRole()","Confirm the evaluator bean is named 'permissionEvaluator' so it is picked up automatically"],"exampleFix":"// before: default DenyAllPermissionEvaluator is used\n@PreAuthorize(\"hasPermission(#doc, 'WRITE')\")\n// after: register a real evaluator\nexpressionHandler.setPermissionEvaluator(new DocumentPermissionEvaluator());\nDefaultMethodSecurityExpressionHandler h = new DefaultMethodSecurityExpressionHandler();\nh.setPermissionEvaluator(new DocumentPermissionEvaluator());","handlingStrategy":"validation","validationCode":"// Fail fast at startup if no real PermissionEvaluator is registered\nPermissionEvaluator pe = expressionHandler.getPermissionEvaluator();\nif (pe instanceof DenyAllPermissionEvaluator) {\n  throw new IllegalStateException(\"Register a custom PermissionEvaluator; current one always denies\");\n}","typeGuard":"boolean hasRealEvaluator(PermissionEvaluator pe) {\n  return pe != null && !(pe instanceof DenyAllPermissionEvaluator);\n}","tryCatchPattern":null,"preventionTips":["Never rely on hasPermission() without registering a custom PermissionEvaluator","Add a startup assertion that the evaluator bean is not the deny-all default","Cover @PreAuthorize hasPermission rules with tests that assert real access decisions"],"tags":["spring-security","method-security","permission-evaluator","access-denied"],"backgroundTag":"permission-denied","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}