{"record":{"id":"d569b3d115c70221","repo":"spring-projects/spring-security","slug":"no-visible-websecurityexpressionhandler-instance-c","errorCode":null,"errorMessage":"No visible WebSecurityExpressionHandler instance could be found in the application context. There must be at least one in order to support expressions in JSP 'authorize' tags.","messagePattern":"No visible WebSecurityExpressionHandler instance could be found in the application context\\. There must be at least one in order to support expressions in JSP 'authorize' tags\\.","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"error","filePath":"taglibs/src/main/java/org/springframework/security/taglibs/authz/AbstractAuthorizeTag.java","lineNumber":206,"sourceCode":"\t\tString[] names = appContext.getBeanNamesForType(SecurityContextHolderStrategy.class);\n\t\tif (names.length == 1) {\n\t\t\tSecurityContextHolderStrategy strategy = appContext.getBean(SecurityContextHolderStrategy.class);\n\t\t\treturn strategy.getContext();\n\t\t}\n\t\treturn SecurityContextHolder.getContext();\n\t}\n\n\t@SuppressWarnings({ \"unchecked\", \"rawtypes\" })\n\tprivate SecurityExpressionHandler<FilterInvocation> getExpressionHandler() throws IOException {\n\t\tApplicationContext appContext = getApplicationContext();\n\t\tMap<String, SecurityExpressionHandler> handlers = appContext.getBeansOfType(SecurityExpressionHandler.class);\n\t\tfor (SecurityExpressionHandler handler : handlers.values()) {\n\t\t\tif (FilterInvocation.class\n\t\t\t\t.equals(GenericTypeResolver.resolveTypeArgument(handler.getClass(), SecurityExpressionHandler.class))) {\n\t\t\t\treturn handler;\n\t\t\t}\n\t\t}\n\t\tthrow new IOException(\"No visible WebSecurityExpressionHandler instance could be found in the application \"\n\t\t\t\t+ \"context. There must be at least one in order to support expressions in JSP 'authorize' tags.\");\n\t}\n\n\tprivate WebInvocationPrivilegeEvaluator getPrivilegeEvaluator() throws IOException {\n\t\tWebInvocationPrivilegeEvaluator privEvaluatorFromRequest = (WebInvocationPrivilegeEvaluator) getRequest()\n\t\t\t.getAttribute(WebAttributes.WEB_INVOCATION_PRIVILEGE_EVALUATOR_ATTRIBUTE);\n\t\tif (privEvaluatorFromRequest != null) {\n\t\t\treturn privEvaluatorFromRequest;\n\t\t}\n\t\tApplicationContext ctx = getApplicationContext();\n\t\tMap<String, WebInvocationPrivilegeEvaluator> wipes = ctx.getBeansOfType(WebInvocationPrivilegeEvaluator.class);\n\t\tif (wipes.isEmpty()) {\n\t\t\tthrow new IOException(\n\t\t\t\t\t\"No visible WebInvocationPrivilegeEvaluator instance could be found in the application \"\n\t\t\t\t\t\t\t+ \"context. There must be at least one in order to support the use of URL access checks in 'authorize' tags.\");\n\t\t}\n\t\treturn (WebInvocationPrivilegeEvaluator) wipes.values().toArray()[0];\n\t}","sourceCodeStart":188,"sourceCodeEnd":224,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/taglibs/src/main/java/org/springframework/security/taglibs/authz/AbstractAuthorizeTag.java#L188-L224","documentation":"JSP 'authorize' tags (spring-security-taglibs) resolve a SecurityExpressionHandler for FilterInvocation from the ApplicationContext to evaluate access expressions. If the application context contains no such handler, the tag throws this IOException — expression-based authorize tags cannot work without a WebSecurity ExpressionHandler bean.","triggerScenarios":"Using <sec:authorize access=\"...\"> in a JSP when getApplicationContext().getBeansOfType(SecurityExpressionHandler.class) has no handler whose type argument resolves to FilterInvocation — typically because Spring Security's web support is not configured in this context at all.","commonSituations":"Spring Security jars on classpath but no @EnableWebSecurity / WebSecurityConfiguration in the application context; tag used in a context that cannot see the root context (wrong parent/child context setup in older Spring MVC); missing spring-security-config/web wiring; using the tag in a portlet or non-web context.","solutions":["Configure Spring Security in the application context (e.g. @EnableWebSecurity with a SecurityFilterChain) so the default WebSecurityExpressionHandler/SecurityExpressionHandler<FilterInvocation> bean is published.","Ensure the JSP/tag context can see the application context where Security is configured (correct ApplicationContext lookup — set the parent context or publish the handler in the same context).","Verify spring-security-web, spring-security-config, and spring-security-taglibs versions are aligned on the classpath.","As a fallback, use the url attribute form only after confirming WebInvocationPrivilegeEvaluator beans exist, or migrate authorization checks to controller/service layer with @PreAuthorize."],"exampleFix":"// before\n// no Spring Security configuration in the web context\n\n// after\n@Configuration\n@EnableWebSecurity\nclass SecurityConfig {\n    @Bean\n    SecurityFilterChain filterChain(HttpSecurity http) throws Exception {\n        http.authorizeHttpRequests(req -> req.anyRequest().authenticated());\n        return http.build();\n    }\n}","handlingStrategy":"try-catch","validationCode":"Map<String, SecurityExpressionHandler> handlers = ctx.getBeansOfType(SecurityExpressionHandler.class);\nif (handlers.values().stream().noneMatch(h -> FilterInvocation.class.equals(\n        GenericTypeResolver.resolveTypeArgument(h.getClass(), SecurityExpressionHandler.class)))) {\n    throw new IllegalStateException(\"No WebSecurityExpressionHandler in context; configure @EnableWebSecurity\");\n}","typeGuard":null,"tryCatchPattern":"try { ... tag evaluation ... } catch (IOException ex) { if (ex.getMessage().contains(\"WebSecurityExpressionHandler\")) { log.error(\"Spring Security web config missing from this context\"); } throw ex; }","preventionTips":["Configure @EnableWebSecurity / SecurityFilterChain so the expression handler bean exists","Ensure the JSP's ApplicationContext is the Security-configured context (or its child)","Keep spring-security-web/config/taglibs versions aligned"],"tags":["jsp","taglibs","spring-security","authorization","missing-bean"],"backgroundTag":"missing-dependency","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}