spring-projects/spring-security · error · IllegalStateException
authorizationManagerFactory must be an instance of…
Error message
authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory
What it means
AbstractSecurityExpressionHandler's deprecated getDefaultAuthorizationManagerFactory() assumes the configured AuthorizationManagerFactory is the default implementation. If a custom AuthorizationManagerFactory was set (setAuthorizationManagerFactory) that is not a DefaultAuthorizationManagerFactory, this deprecated accessor throws IllegalStateException.
Solutions
- Stop using the deprecated getDefaultAuthorizationManagerFactory(); configure the role hierarchy via the AuthorizationManagerFactory or on the expression handler directly
- Either remove the custom AuthorizationManagerFactory so the default is used, or make the custom factory extend DefaultAuthorizationManagerFactory
- Refactor callers (e.g. custom setRoleHierarchy overrides) to the new AuthorizationManagerFactory-based API
Example fix
// before
handler.setAuthorizationManagerFactory(new CustomAuthorizationManagerFactory<>());
DefaultAuthorizationManagerFactory<T> amf = handler.getDefaultAuthorizationManagerFactory(); // throws
// after
handler.setRoleHierarchy(new RoleHierarchyImpl("ROLE_A > ROLE_B")); // use non-deprecated API, avoid the deprecated accessor Defensive patterns
Strategy: type-guard
Validate before calling
if (!(handler instanceof AbstractSecurityExpressionHandler<?> aseh)
|| !(isDefaultAuthorizationManagerFactory(aseh))) {
// use the new AuthorizationManagerFactory API instead
} Type guard
boolean isDefaultAuthorizationManagerFactory(AbstractSecurityExpressionHandler<?> h) {
try {
java.lang.reflect.Field f = AbstractSecurityExpressionHandler.class.getDeclaredField("authorizationManagerFactory");
f.setAccessible(true);
return f.get(h) instanceof DefaultAuthorizationManagerFactory;
} catch (ReflectiveOperationException e) {
return false;
}
} Try / catch
try {
DefaultAuthorizationManagerFactory<T> amf = handler.getDefaultAuthorizationManagerFactory();
} catch (IllegalStateException e) {
// custom AuthorizationManagerFactory in use; migrate to setAuthorizationManagerFactory API
} Prevention
- Avoid the @Deprecated getDefaultAuthorizationManagerFactory accessor after Spring Security 7
- Only call it when you know the default factory was not replaced
- Keep role hierarchy and authorization manager customization on one consistent API surface
When it happens
Trigger: Calling getDefaultAuthorizationManagerFactory() (directly or via setRoleHierarchy wiring that relies on it) after having installed a custom AuthorizationManagerFactory implementation via setAuthorizationManagerFactory.
Common situations: Legacy code (pre-7.0 style) customizing role hierarchy while newer code on the same handler swapped in a non-default AuthorizationManagerFactory; migrating to Spring Security 7 with mixed legacy and new APIs.
Understand the failure class
Background: "is deprecated and will be removed" — deprecation warnings for old API names, keywords, and options, and how to migrate before the removal release — this error's family across 29 libraries.
Related errors
- authorizationManagerFactory must be an instance of…
- Access Denied
- Access is denied
- Access is denied
- Access is denied
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/25d1dccb6a50c0bf.
Report an issue: GitHub.
Appendix: source
Thrown at core/src/main/java/org/springframework/security/access/expression/AbstractSecurityExpressionHandler.java:140
}
protected final AuthorizationManagerFactory<T> getAuthorizationManagerFactory() {
return this.authorizationManagerFactory;
}
/**
* Allows accessing the {@link DefaultAuthorizationManagerFactory} for getting and
* setting defaults. This method will be removed in Spring Security 8.
* @return the {@link DefaultAuthorizationManagerFactory}
* @throws IllegalStateException if a different {@link AuthorizationManagerFactory}
* was already set
* @deprecated Use
* {@link #setAuthorizationManagerFactory(AuthorizationManagerFactory)} instead
*/
@Deprecated(since = "7.0")
protected final DefaultAuthorizationManagerFactory<T> getDefaultAuthorizationManagerFactory() {
if (!(this.authorizationManagerFactory instanceof DefaultAuthorizationManagerFactory<T> defaultAuthorizationManagerFactory)) {
throw new IllegalStateException(
"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory");
}
return defaultAuthorizationManagerFactory;
}
/**
* Returns the {@link RoleHierarchy} to use.
* @deprecated Use {@link #getDefaultAuthorizationManagerFactory()} instead
*/
@Deprecated(since = "7.0")
protected @Nullable RoleHierarchy getRoleHierarchy() {
return this.roleHierarchy;
}
/**
* Sets the {@link RoleHierarchy} to use.
* @deprecated UseView on GitHub (pinned to 96852e8860)