{"record":{"id":"92844b6405677367","repo":"spring-projects/spring-security","slug":"authentication-method-not-supported-request-met","errorCode":null,"errorMessage":"Authentication method not supported: ${request.method}","messagePattern":"Authentication method not supported: (.+?)","errorType":"exception","errorClass":"AuthenticationServiceException","httpStatus":null,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/authentication/UsernamePasswordAuthenticationFilter.java","lineNumber":77,"sourceCode":"\tprivate String usernameParameter = SPRING_SECURITY_FORM_USERNAME_KEY;\n\n\tprivate String passwordParameter = SPRING_SECURITY_FORM_PASSWORD_KEY;\n\n\tprivate boolean postOnly = true;\n\n\tpublic UsernamePasswordAuthenticationFilter() {\n\t\tsuper(DEFAULT_PATH_REQUEST_MATCHER);\n\t}\n\n\tpublic UsernamePasswordAuthenticationFilter(AuthenticationManager authenticationManager) {\n\t\tsuper(DEFAULT_PATH_REQUEST_MATCHER, authenticationManager);\n\t}\n\n\t@Override\n\tpublic Authentication attemptAuthentication(HttpServletRequest request, HttpServletResponse response)\n\t\t\tthrows AuthenticationException {\n\t\tif (this.postOnly && !request.getMethod().equals(\"POST\")) {\n\t\t\tthrow new AuthenticationServiceException(\"Authentication method not supported: \" + request.getMethod());\n\t\t}\n\t\tString username = obtainUsername(request);\n\t\tusername = (username != null) ? username.trim() : \"\";\n\t\tString password = obtainPassword(request);\n\t\tpassword = (password != null) ? password : \"\";\n\t\tUsernamePasswordAuthenticationToken authRequest = UsernamePasswordAuthenticationToken.unauthenticated(username,\n\t\t\t\tpassword);\n\t\t// Allow subclasses to set the \"details\" property\n\t\tsetDetails(request, authRequest);\n\t\treturn this.getAuthenticationManager().authenticate(authRequest);\n\t}\n\n\t/**\n\t * Enables subclasses to override the composition of the password, such as by\n\t * including additional values and a separator.\n\t * <p>\n\t * This might be used for example if a postcode/zipcode was required in addition to\n\t * the password. A delimiter such as a pipe (|) should be used to separate the","sourceCodeStart":59,"sourceCodeEnd":95,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/authentication/UsernamePasswordAuthenticationFilter.java#L59-L95","documentation":"UsernamePasswordAuthenticationFilter.attemptAuthentication() only accepts POST requests when postOnly is true (the default). Any other HTTP method (GET, PUT, ...) throws AuthenticationServiceException with the offending method, which surfaces as HTTP 500 unless handled, rather than a normal authentication failure.","triggerScenarios":"Submitting the login form via GET (missing method=\"POST\" on the form), a redirect turning POST into GET, API clients calling the login URL with the wrong verb, or postOnly left default while the frontend uses another method.","commonSituations":"HTML forms without an explicit method attribute default to GET; login links (href) instead of form submissions; misconfigured proxies/CDNs rewriting methods; custom frontends sending PUT/JSON to the form-login endpoint.","solutions":["Set the login form/HTTP client to POST: <form method=\"post\" action=\"/login\">","If non-POST methods are genuinely required, call filter.setPostOnly(false)","For JSON login, use a filter configured with an appropriate converter rather than form login, or a custom attemptAuthentication","Check for redirects (301/302) that convert POST to GET and fix the client to POST directly to the target"],"exampleFix":"// before\n<form action=\"/login\"> ... </form>\n// after\n<form method=\"post\" action=\"/login\"> ... </form>","handlingStrategy":"validation","validationCode":"if (!\"POST\".equalsIgnoreCase(request.getMethod())) {\n    throw new IllegalStateException(\"Login must be submitted via POST\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    chain.doFilter(request, response, chain);\n} catch (AuthenticationServiceException e) {\n    if (e.getMessage() != null && e.getMessage().startsWith(\"Authentication method not supported\")) {\n        response.sendError(HttpServletResponse.SC_METHOD_NOT_ALLOWED);\n        return;\n    }\n    throw e;\n}","preventionTips":["Always set method=\"post\" on login forms","Never trigger login via links/GET requests","Call setPostOnly(false) only deliberately","Check redirects do not downgrade POST to GET"],"tags":["spring-security","form-login","http-method","post-only"],"backgroundTag":"unsupported-operation","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}