spring-projects/spring-security · warning

Denying user permission ' ' on object

Error message

Denying user %s permission '%s' on object %s

What it means

DenyAllPermissionEvaluator is a fail-closed PermissionEvaluator that always returns false for hasPermission(authentication, target, permission), logging who and what was denied. It exists so that SpEL @PreAuthorize("hasPermission(...)" expressions fail safe when no real evaluator is registered.

Solutions

  1. Implement a custom PermissionEvaluator and register it via .expressionHandler() / a DefaultMethodSecurityExpressionHandler with your evaluator set
  2. If SpEL hasPermission is not intended, replace expressions with role/authority checks like hasRole()
  3. Confirm the evaluator bean is named 'permissionEvaluator' so it is picked up automatically

Example fix

// before: default DenyAllPermissionEvaluator is used
@PreAuthorize("hasPermission(#doc, 'WRITE')")
// after: register a real evaluator
expressionHandler.setPermissionEvaluator(new DocumentPermissionEvaluator());
DefaultMethodSecurityExpressionHandler h = new DefaultMethodSecurityExpressionHandler();
h.setPermissionEvaluator(new DocumentPermissionEvaluator());
Defensive patterns

Strategy: validation

Validate before calling

// Fail fast at startup if no real PermissionEvaluator is registered
PermissionEvaluator pe = expressionHandler.getPermissionEvaluator();
if (pe instanceof DenyAllPermissionEvaluator) {
  throw new IllegalStateException("Register a custom PermissionEvaluator; current one always denies");
}

Type guard

boolean hasRealEvaluator(PermissionEvaluator pe) {
  return pe != null && !(pe instanceof DenyAllPermissionEvaluator);
}

Prevention

When it happens

Trigger: A method-security or SpEL expression calls hasPermission('#target', 'permission') while the only registered PermissionEvaluator is DenyAllPermissionEvaluator (the default when none is configured).

Common situations: Developers using hasPermission() in @PreAuthorize/@PostAuthorize without registering a custom PermissionEvaluator; bean named permissionEvaluator missing from the context.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/7e96045bee51b7c5. Report an issue: GitHub.

Appendix: source

Thrown at core/src/main/java/org/springframework/security/access/expression/DenyAllPermissionEvaluator.java:46

/**
 * A null PermissionEvaluator which denies all access. Used by default for situations when
 * permission evaluation should not be required.
 *
 * @author Luke Taylor
 * @since 3.0
 */
public class DenyAllPermissionEvaluator implements PermissionEvaluator {

	private final Log logger = LogFactory.getLog(getClass());

	/**
	 * Always denies permission.
	 * @return false always
	 */
	@Override
	public boolean hasPermission(Authentication authentication, @Nullable Object target, Object permission) {
		this.logger.warn(LogMessage.format("Denying user %s permission '%s' on object %s", authentication.getName(),
				permission, target));
		return false;
	}

	/**
	 * Always denies permission.
	 * @return false always
	 */
	@Override
	public boolean hasPermission(Authentication authentication, Serializable targetId, String targetType,
			Object permission) {
		this.logger.warn(LogMessage.format("Denying user %s permission '%s' on object with Id %s",
				authentication.getName(), permission, targetId));
		return false;
	}

}

View on GitHub (pinned to 96852e8860)