spring-projects/spring-security · error · IllegalStateException

authorizationManagerFactory must be an instance of…

Error message

authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory

What it means

AbstractSecurityExpressionHandler's deprecated getDefaultAuthorizationManagerFactory() assumes the configured AuthorizationManagerFactory is the default implementation. If a custom AuthorizationManagerFactory was set (setAuthorizationManagerFactory) that is not a DefaultAuthorizationManagerFactory, this deprecated accessor throws IllegalStateException.

Solutions

  1. Stop using the deprecated getDefaultAuthorizationManagerFactory(); configure the role hierarchy via the AuthorizationManagerFactory or on the expression handler directly
  2. Either remove the custom AuthorizationManagerFactory so the default is used, or make the custom factory extend DefaultAuthorizationManagerFactory
  3. Refactor callers (e.g. custom setRoleHierarchy overrides) to the new AuthorizationManagerFactory-based API

Example fix

// before
handler.setAuthorizationManagerFactory(new CustomAuthorizationManagerFactory<>());
DefaultAuthorizationManagerFactory<T> amf = handler.getDefaultAuthorizationManagerFactory(); // throws

// after
handler.setRoleHierarchy(new RoleHierarchyImpl("ROLE_A > ROLE_B")); // use non-deprecated API, avoid the deprecated accessor
Defensive patterns

Strategy: type-guard

Validate before calling

if (!(handler instanceof AbstractSecurityExpressionHandler<?> aseh)
    || !(isDefaultAuthorizationManagerFactory(aseh))) {
  // use the new AuthorizationManagerFactory API instead
}

Type guard

boolean isDefaultAuthorizationManagerFactory(AbstractSecurityExpressionHandler<?> h) {
  try {
    java.lang.reflect.Field f = AbstractSecurityExpressionHandler.class.getDeclaredField("authorizationManagerFactory");
    f.setAccessible(true);
    return f.get(h) instanceof DefaultAuthorizationManagerFactory;
  } catch (ReflectiveOperationException e) {
    return false;
  }
}

Try / catch

try {
  DefaultAuthorizationManagerFactory<T> amf = handler.getDefaultAuthorizationManagerFactory();
} catch (IllegalStateException e) {
  // custom AuthorizationManagerFactory in use; migrate to setAuthorizationManagerFactory API
}

Prevention

When it happens

Trigger: Calling getDefaultAuthorizationManagerFactory() (directly or via setRoleHierarchy wiring that relies on it) after having installed a custom AuthorizationManagerFactory implementation via setAuthorizationManagerFactory.

Common situations: Legacy code (pre-7.0 style) customizing role hierarchy while newer code on the same handler swapped in a non-default AuthorizationManagerFactory; migrating to Spring Security 7 with mixed legacy and new APIs.

Understand the failure class

Background: "is deprecated and will be removed" — deprecation warnings for old API names, keywords, and options, and how to migrate before the removal release — this error's family across 29 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/25d1dccb6a50c0bf. Report an issue: GitHub.

Appendix: source

Thrown at core/src/main/java/org/springframework/security/access/expression/AbstractSecurityExpressionHandler.java:140

	}

	protected final AuthorizationManagerFactory<T> getAuthorizationManagerFactory() {
		return this.authorizationManagerFactory;
	}

	/**
	 * Allows accessing the {@link DefaultAuthorizationManagerFactory} for getting and
	 * setting defaults. This method will be removed in Spring Security 8.
	 * @return the {@link DefaultAuthorizationManagerFactory}
	 * @throws IllegalStateException if a different {@link AuthorizationManagerFactory}
	 * was already set
	 * @deprecated Use
	 * {@link #setAuthorizationManagerFactory(AuthorizationManagerFactory)} instead
	 */
	@Deprecated(since = "7.0")
	protected final DefaultAuthorizationManagerFactory<T> getDefaultAuthorizationManagerFactory() {
		if (!(this.authorizationManagerFactory instanceof DefaultAuthorizationManagerFactory<T> defaultAuthorizationManagerFactory)) {
			throw new IllegalStateException(
					"authorizationManagerFactory must be an instance of DefaultAuthorizationManagerFactory");
		}

		return defaultAuthorizationManagerFactory;
	}

	/**
	 * Returns the {@link RoleHierarchy} to use.
	 * @deprecated Use {@link #getDefaultAuthorizationManagerFactory()} instead
	 */
	@Deprecated(since = "7.0")
	protected @Nullable RoleHierarchy getRoleHierarchy() {
		return this.roleHierarchy;
	}

	/**
	 * Sets the {@link RoleHierarchy} to use.
	 * @deprecated Use

View on GitHub (pinned to 96852e8860)