{"record":{"id":"b886de1e06359e5d","repo":"spring-projects/spring-security","slug":"unsupported-element-of-type-element-getclass","errorCode":null,"errorMessage":"Unsupported element of type \" + element.getClass()","messagePattern":"Unsupported element of type \" \\+ element\\.getClass\\(\\)","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"core/src/main/java/org/springframework/security/core/annotation/ExpressionTemplateSecurityAnnotationScanner.java","lineNumber":115,"sourceCode":"\t}\n\n\t@Override\n\t@Nullable MergedAnnotation<A> merge(AnnotatedElement element, @Nullable Class<?> targetClass) {\n\t\tif (element instanceof Parameter parameter) {\n\t\t\tMergedAnnotation<A> annotation = this.unique.merge(parameter, targetClass);\n\t\t\tif (annotation == null) {\n\t\t\t\treturn null;\n\t\t\t}\n\t\t\treturn resolvePlaceholders(annotation);\n\t\t}\n\t\tif (element instanceof Method method) {\n\t\t\tMergedAnnotation<A> annotation = this.unique.merge(method, targetClass);\n\t\t\tif (annotation == null) {\n\t\t\t\treturn null;\n\t\t\t}\n\t\t\treturn resolvePlaceholders(annotation);\n\t\t}\n\t\tthrow new IllegalArgumentException(\"Unsupported element of type \" + element.getClass());\n\t}\n\n\tprivate MergedAnnotation<A> resolvePlaceholders(MergedAnnotation<A> mergedAnnotation) {\n\t\tif (this.templateDefaults == null) {\n\t\t\treturn mergedAnnotation;\n\t\t}\n\t\tif (mergedAnnotation.getMetaSource() == null) {\n\t\t\treturn mergedAnnotation;\n\t\t}\n\t\tPropertyPlaceholderHelper helper = new PropertyPlaceholderHelper(\"{\", \"}\", null, null,\n\t\t\t\tthis.templateDefaults.isIgnoreUnknown());\n\t\tMap<String, Object> properties = new HashMap<>(mergedAnnotation.asMap());\n\t\tMap<String, String> metaAnnotationProperties = extractMetaAnnotationProperties(mergedAnnotation);\n\t\tfor (Map.Entry<String, Object> annotationProperty : mergedAnnotation.asMap().entrySet()) {\n\t\t\tif (!(annotationProperty.getValue() instanceof String expression)) {\n\t\t\t\tcontinue;\n\t\t\t}\n\t\t\tString value = helper.replacePlaceholders(expression, metaAnnotationProperties::get);","sourceCodeStart":97,"sourceCodeEnd":133,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/core/src/main/java/org/springframework/security/core/annotation/ExpressionTemplateSecurityAnnotationScanner.java#L97-L133","documentation":"ExpressionTemplateSecurityAnnotationScanner.merge only supports Class or Method annotated elements. When given any other AnnotatedElement type (e.g. Field, Package, Parameter) it throws IllegalArgumentException because template-based security annotation scanning is only defined for classes and methods.","triggerScenarios":"Passing a non-Class/non-Method element (Field, Constructor, Parameter, etc.) to the scanner's merge method — typically via a custom pointcut or security-metadata source that hands the scanner arbitrary reflective elements.","commonSituations":"Custom AuthorizeReactiveMethodInterceptor / authorization metadata lookup over fields or parameters; framework code that scans annotations on unusual element types.","solutions":["Restrict the element passed to the scanner to Class or Method","If you need field/parameter-level security, implement a custom SecurityAnnotationScanner that handles those types","Check upstream code (e.g. custom MethodSecurityMetadataSource) and filter unsupported elements before calling merge"],"exampleFix":"// before\nscanner.merge(field, targetClass);\n// after\nif (element instanceof Class || element instanceof Method) {\n    scanner.merge(element, targetClass);\n}","handlingStrategy":"type-guard","validationCode":"if (!(element instanceof Class) && !(element instanceof Method)) { return null; }","typeGuard":"boolean isSupportedElement(AnnotatedElement e) { return e instanceof Class || e instanceof Method; }","tryCatchPattern":null,"preventionTips":["Only pass Class or Method elements to security annotation scanners","Filter reflective elements before invoking the scanner","Don't attempt field/parameter-level security scanning with this scanner"],"tags":["annotation-scanning","unsupported-type","authorization"],"backgroundTag":"unsupported-operation","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}