spring-projects/spring-security · warning
Denying user permission ' ' on object
Error message
Denying user %s permission '%s' on object %s
What it means
DenyAllPermissionEvaluator is a fail-closed PermissionEvaluator that always returns false for hasPermission(authentication, target, permission), logging who and what was denied. It exists so that SpEL @PreAuthorize("hasPermission(...)" expressions fail safe when no real evaluator is registered.
Solutions
- Implement a custom PermissionEvaluator and register it via .expressionHandler() / a DefaultMethodSecurityExpressionHandler with your evaluator set
- If SpEL hasPermission is not intended, replace expressions with role/authority checks like hasRole()
- Confirm the evaluator bean is named 'permissionEvaluator' so it is picked up automatically
Example fix
// before: default DenyAllPermissionEvaluator is used
@PreAuthorize("hasPermission(#doc, 'WRITE')")
// after: register a real evaluator
expressionHandler.setPermissionEvaluator(new DocumentPermissionEvaluator());
DefaultMethodSecurityExpressionHandler h = new DefaultMethodSecurityExpressionHandler();
h.setPermissionEvaluator(new DocumentPermissionEvaluator()); Defensive patterns
Strategy: validation
Validate before calling
// Fail fast at startup if no real PermissionEvaluator is registered
PermissionEvaluator pe = expressionHandler.getPermissionEvaluator();
if (pe instanceof DenyAllPermissionEvaluator) {
throw new IllegalStateException("Register a custom PermissionEvaluator; current one always denies");
} Type guard
boolean hasRealEvaluator(PermissionEvaluator pe) {
return pe != null && !(pe instanceof DenyAllPermissionEvaluator);
} Prevention
- Never rely on hasPermission() without registering a custom PermissionEvaluator
- Add a startup assertion that the evaluator bean is not the deny-all default
- Cover @PreAuthorize hasPermission rules with tests that assert real access decisions
When it happens
Trigger: A method-security or SpEL expression calls hasPermission('#target', 'permission') while the only registered PermissionEvaluator is DenyAllPermissionEvaluator (the default when none is configured).
Common situations: Developers using hasPermission() in @PreAuthorize/@PostAuthorize without registering a custom PermissionEvaluator; bean named permissionEvaluator missing from the context.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
- Denying user permission ' ' on object with Id
- Access Denied
- Access is denied
- Access is denied
- Access is denied
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/7e96045bee51b7c5.
Report an issue: GitHub.
Appendix: source
Thrown at core/src/main/java/org/springframework/security/access/expression/DenyAllPermissionEvaluator.java:46
/**
* A null PermissionEvaluator which denies all access. Used by default for situations when
* permission evaluation should not be required.
*
* @author Luke Taylor
* @since 3.0
*/
public class DenyAllPermissionEvaluator implements PermissionEvaluator {
private final Log logger = LogFactory.getLog(getClass());
/**
* Always denies permission.
* @return false always
*/
@Override
public boolean hasPermission(Authentication authentication, @Nullable Object target, Object permission) {
this.logger.warn(LogMessage.format("Denying user %s permission '%s' on object %s", authentication.getName(),
permission, target));
return false;
}
/**
* Always denies permission.
* @return false always
*/
@Override
public boolean hasPermission(Authentication authentication, Serializable targetId, String targetType,
Object permission) {
this.logger.warn(LogMessage.format("Denying user %s permission '%s' on object with Id %s",
authentication.getName(), permission, targetId));
return false;
}
}
View on GitHub (pinned to 96852e8860)