{"record":{"id":"af1b277fe362e219","repo":"spring-projects/spring-security","slug":"ex-getmessage","errorCode":null,"errorMessage":"<ex.getMessage()>","messagePattern":"<ex\\.getMessage\\(\\)>","errorType":"exception","errorClass":"ServletException","httpStatus":null,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/servletapi/HttpServlet3RequestFactory.java","lineNumber":266,"sourceCode":"\t\t\tSecurityContext context = HttpServlet3RequestFactory.this.securityContextHolderStrategy\n\t\t\t\t.createEmptyContext();\n\t\t\tcontext.setAuthentication(authentication);\n\t\t\tHttpServlet3RequestFactory.this.securityContextHolderStrategy.setContext(context);\n\t\t\tHttpServlet3RequestFactory.this.securityContextRepository.saveContext(context, this, this.response);\n\t\t}\n\n\t\tprivate Authentication getAuthentication(AuthenticationManager authManager, String username, String password)\n\t\t\t\tthrows ServletException {\n\t\t\ttry {\n\t\t\t\tUsernamePasswordAuthenticationToken authentication = UsernamePasswordAuthenticationToken\n\t\t\t\t\t.unauthenticated(username, password);\n\t\t\t\tObject details = HttpServlet3RequestFactory.this.authenticationDetailsSource.buildDetails(this);\n\t\t\t\tauthentication.setDetails(details);\n\t\t\t\treturn authManager.authenticate(authentication);\n\t\t\t}\n\t\t\tcatch (AuthenticationException ex) {\n\t\t\t\tHttpServlet3RequestFactory.this.securityContextHolderStrategy.clearContext();\n\t\t\t\tthrow new ServletException(ex.getMessage(), ex);\n\t\t\t}\n\t\t}\n\n\t\t@Override\n\t\tpublic void logout() throws ServletException {\n\t\t\tList<LogoutHandler> handlers = HttpServlet3RequestFactory.this.logoutHandlers;\n\t\t\tif (CollectionUtils.isEmpty(handlers)) {\n\t\t\t\tHttpServlet3RequestFactory.this.logger\n\t\t\t\t\t.debug(\"logoutHandlers is null, so allowing original HttpServletRequest to handle logout\");\n\t\t\t\tsuper.logout();\n\t\t\t\treturn;\n\t\t\t}\n\t\t\tAuthentication authentication = HttpServlet3RequestFactory.this.securityContextHolderStrategy.getContext()\n\t\t\t\t.getAuthentication();\n\t\t\tfor (LogoutHandler handler : handlers) {\n\t\t\t\thandler.logout(this, this.response, authentication);\n\t\t\t}\n\t\t}","sourceCodeStart":248,"sourceCodeEnd":284,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/servletapi/HttpServlet3RequestFactory.java#L248-L284","documentation":"When the wrapper's getAuthentication() delegates to the configured AuthenticationManager and authentication fails (AuthenticationException), the security context is cleared and the exception is rethrown as a ServletException whose message is the original exception message, with the original as cause. This exposes programmatic-authentication failures to the servlet API caller while ensuring no stale authentication remains.","triggerScenarios":"Calling request.authenticate(request)/the wrapper's authentication path when the AuthenticationManager rejects the credentials or token — e.g. BadCredentialsException, DisabledException, LockedException raised inside authenticate().","commonSituations":"Wrong username/password supplied to programmatic login; account disabled/locked/expired; an AuthenticationProvider throwing due to misconfiguration; token no longer valid at authenticate() time.","solutions":["Inspect the ServletException cause for the concrete AuthenticationException subclass and message","Correct the credentials or account state the caller supplied","Catch ServletException and map to an appropriate login-failure response instead of a 500","Verify AuthenticationManager/provider configuration if even valid credentials fail"],"exampleFix":"// before\nrequest.authenticate(response);\n// after\ntry {\n    request.authenticate(response);\n} catch (ServletException e) {\n    logger.warn(\"Authentication failed: \" + e.getMessage());\n    // render login-failure view\n}","handlingStrategy":"try-catch","validationCode":"// validate credentials are present before attempting authentication\nif (username == null || username.isBlank() || password == null || password.isEmpty()) {\n    throw new IllegalArgumentException(\"Username and password required\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    request.login(user, pass);\n    return true;\n} catch (ServletException ex) {\n    Throwable cause = ex.getCause();\n    if (cause instanceof AuthenticationException authEx) {\n        // e.g. BadCredentialsException, DisabledException\n        return handleAuthFailure(authEx);\n    }\n    throw ex;\n}","preventionTips":["Always inspect getCause() for the concrete AuthenticationException type","Give users actionable messages (account locked vs bad credentials) based on the cause","Pre-clear the SecurityContext before programmatic re-authentication","Test login failure paths (locked, disabled, expired accounts) in integration tests"],"tags":["spring-security","authentication","servlet-api"],"backgroundTag":"authentication-required","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}