{"record":{"id":"f7bdad470aaf494e","repo":"spring-projects/spring-security","slug":"this-map-only-supports-the-following-keys-thi","errorCode":null,"errorMessage":"This map only supports the following keys: \" + this.loaders.keySet()","messagePattern":"This map only supports the following keys: \" \\+ this\\.loaders\\.keySet\\(\\)","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"config/src/main/java/org/springframework/security/config/annotation/web/configuration/SecurityReactorContextConfiguration.java","lineNumber":238,"sourceCode":"\t\t@Override\n\t\tpublic boolean isEmpty() {\n\t\t\treturn this.loaders.isEmpty();\n\t\t}\n\n\t\t@Override\n\t\tpublic boolean containsKey(Object key) {\n\t\t\treturn this.loaders.containsKey(key);\n\t\t}\n\n\t\t@Override\n\t\tpublic Set<K> keySet() {\n\t\t\treturn this.loaders.keySet();\n\t\t}\n\n\t\t@Override\n\t\tpublic V get(Object key) {\n\t\t\tif (!this.loaders.containsKey(key)) {\n\t\t\t\tthrow new IllegalArgumentException(\n\t\t\t\t\t\t\"This map only supports the following keys: \" + this.loaders.keySet());\n\t\t\t}\n\t\t\treturn this.loaded.computeIfAbsent((K) key, (k) -> this.loaders.get(k).get());\n\t\t}\n\n\t\t@Override\n\t\tpublic V put(K key, V value) {\n\t\t\tif (!this.loaders.containsKey(key)) {\n\t\t\t\tthrow new IllegalArgumentException(\n\t\t\t\t\t\t\"This map only supports the following keys: \" + this.loaders.keySet());\n\t\t\t}\n\t\t\treturn this.loaded.put(key, value);\n\t\t}\n\n\t\t@Override\n\t\tpublic V remove(Object key) {\n\t\t\tif (!this.loaders.containsKey(key)) {\n\t\t\t\tthrow new IllegalArgumentException(","sourceCodeStart":220,"sourceCodeEnd":256,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/config/src/main/java/org/springframework/security/config/annotation/web/configuration/SecurityReactorContextConfiguration.java#L220-L256","documentation":"SecurityReactorContextConfiguration uses an internal read-only map view (with a computeIfAbsent loader cache) that only accepts keys corresponding to registered loaders. get() with an unknown key throws IllegalArgumentException listing the supported keys. Callers are expected to only look up keys produced by keySet().","triggerScenarios":"Calling get(key) on this map with a key not present in loaders.keySet(); passing a Reactor context key of the wrong type or from a different security module; external code treating the map as a general-purpose Map.","commonSituations":"Custom WebFlux/Reactor code reading the security Reactor context with hand-built keys; version mismatches where the loader key class changed between Spring Security versions; reflection-based access to the internal map.","solutions":["Only query keys obtained from the map's keySet() (the security context loader keys Spring Security registers)","Use the public Reactor Context API (context.get(SecurityContext.class) style accessors) instead of touching the internal map","Align Spring Security versions so the loader key classes match those registered"],"exampleFix":"// before\nObject v = securityLoaders.get(myArbitraryKey);\n// after\nif (securityLoaders.keySet().contains(myArbitraryKey)) {\n    Object v = securityLoaders.get(myArbitraryKey);\n}","handlingStrategy":"type-guard","validationCode":"if (map != null && map.keySet().contains(key)) {\n    V value = map.get(key);\n}","typeGuard":"static <K,V> boolean isSupportedKey(Map<K,V> map, Object key) {\n    return map != null && map.keySet().contains(key);\n}","tryCatchPattern":"try {\n    value = loadersMap.get(key);\n} catch (IllegalArgumentException e) {\n    if (e.getMessage().startsWith(\"This map only supports the following keys\")) {\n        value = null; // key not managed by security context loaders\n    } else throw e;\n}","preventionTips":["Only look up keys obtained from keySet() or the official Reactor Context API","Avoid touching internal security context maps; prefer context.getOrDefault on Reactor Context","Keep Spring Security versions consistent across modules so loader key classes match"],"tags":["spring-security","webflux","reactor-context","map-access"],"backgroundTag":"invalid-argument-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}