spring-projects/spring-security · error · IllegalArgumentException

The name of the password encoder is improperly formatted or…

Error message

The name of the password encoder is improperly formatted or incomplete. The format should be '%sENCODER%spassword'.

What it means

The stored password contains the prefix or suffix somewhere but is not a well-formed '{id}password' string (e.g. prefix present without suffix, or suffix before prefix). The id cannot be extracted, so the fallback matcher throws this IllegalArgumentException describing the required format.

Solutions

  1. Rewrite the stored value as a complete '{id}encodedPassword' string and verify it parses (extract the id between '{' and first '}')
  2. Check whether the column length truncated the value and widen the column, then re-encode the password
  3. Regenerate the credential using delegatingPasswordEncoder.encode(rawPassword) so the format is guaranteed correct
  4. Check for accidental double braces and strip the extra layer

Example fix

// before
// stored (truncated): '{bcrypt$2a$10$dXJ3'
// after
// stored: '{bcrypt}$2a$10$dXJ3SW6G7P50lGmMkkmwe.20cQQubK3.HZWzG3YB1tlRy.fqvM/BG'
Defensive patterns

Strategy: validation

Validate before calling

boolean wellFormed = storedPassword != null
        && storedPassword.startsWith("{")
        && storedPassword.indexOf('}') > 1;
if (!wellFormed) {
    log.warn("Malformed stored password, missing {id} wrapper");
}

Try / catch

try {
    return encoder.matches(rawPassword, storedPassword);
} catch (IllegalArgumentException e) {
    log.error("Stored password not in '{id}password' format: {}", e.getMessage());
    return false;
}

Prevention

When it happens

Trigger: matches() with a prefixEncodedPassword such as '{bcrypt$2a$...' (missing '}'), 'bcrypt}...' (missing '{'), or '{bcrypt' — strings where indexOf(idPrefix) or indexOf(idSuffix) checks pass individually but no valid '{id}' segment exists.

Common situations: Manual string manipulation/truncation of stored passwords (column length limits cutting off the tail); accidental double-prefixing like '{{noop}secret'; encoding artifacts or data corruption in the credentials column.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/707216669d6e9854. Report an issue: GitHub.

Appendix: source

Thrown at crypto/src/main/java/org/springframework/security/crypto/password/DelegatingPasswordEncoder.java:307

		@Override
		protected String encodeNonNullPassword(String rawPassword) {
			throw new UnsupportedOperationException("encode is not supported");
		}

		@Override
		protected boolean matchesNonNull(String rawPassword, String prefixEncodedPassword) {
			String id = extractId(prefixEncodedPassword);
			if (id != null && !id.isBlank()) {
				throw new IllegalArgumentException(String.format(NO_PASSWORD_ENCODER_MAPPED, id));
			}
			if (prefixEncodedPassword != null && !prefixEncodedPassword.isBlank()) {
				int start = prefixEncodedPassword.indexOf(DelegatingPasswordEncoder.this.idPrefix);
				int end = prefixEncodedPassword.indexOf(DelegatingPasswordEncoder.this.idSuffix, start);
				if (start < 0 && end < 0) {
					throw new IllegalArgumentException(NO_PASSWORD_ENCODER_PREFIX);
				}
			}
			throw new IllegalArgumentException(String.format(MALFORMED_PASSWORD_ENCODER_PREFIX,
					DelegatingPasswordEncoder.this.idPrefix, DelegatingPasswordEncoder.this.idSuffix));
		}

	}

}

View on GitHub (pinned to 96852e8860)