spring-projects/spring-security · error · IllegalArgumentException
This map only supports the following keys: " +…
Error message
This map only supports the following keys: " + this.loaders.keySet()
What it means
SecurityReactorContextConfiguration uses an internal read-only map view (with a computeIfAbsent loader cache) that only accepts keys corresponding to registered loaders. get() with an unknown key throws IllegalArgumentException listing the supported keys. Callers are expected to only look up keys produced by keySet().
Solutions
- Only query keys obtained from the map's keySet() (the security context loader keys Spring Security registers)
- Use the public Reactor Context API (context.get(SecurityContext.class) style accessors) instead of touching the internal map
- Align Spring Security versions so the loader key classes match those registered
Example fix
// before
Object v = securityLoaders.get(myArbitraryKey);
// after
if (securityLoaders.keySet().contains(myArbitraryKey)) {
Object v = securityLoaders.get(myArbitraryKey);
} Defensive patterns
Strategy: type-guard
Validate before calling
if (map != null && map.keySet().contains(key)) {
V value = map.get(key);
} Type guard
static <K,V> boolean isSupportedKey(Map<K,V> map, Object key) {
return map != null && map.keySet().contains(key);
} Try / catch
try {
value = loadersMap.get(key);
} catch (IllegalArgumentException e) {
if (e.getMessage().startsWith("This map only supports the following keys")) {
value = null; // key not managed by security context loaders
} else throw e;
} Prevention
- Only look up keys obtained from keySet() or the official Reactor Context API
- Avoid touching internal security context maps; prefer context.getOrDefault on Reactor Context
- Keep Spring Security versions consistent across modules so loader key classes match
When it happens
Trigger: Calling get(key) on this map with a key not present in loaders.keySet(); passing a Reactor context key of the wrong type or from a different security module; external code treating the map as a general-purpose Map.
Common situations: Custom WebFlux/Reactor code reading the security Reactor context with hand-built keys; version mismatches where the loader key class changed between Spring Security versions; reflection-based access to the internal map.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- Invalid Authorization Grant Type
- invalid_token
- missing_user_info_uri
- missing_user_name_attribute
- is not assignable to
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/f7bdad470aaf494e.
Report an issue: GitHub.
Appendix: source
Thrown at config/src/main/java/org/springframework/security/config/annotation/web/configuration/SecurityReactorContextConfiguration.java:238
@Override
public boolean isEmpty() {
return this.loaders.isEmpty();
}
@Override
public boolean containsKey(Object key) {
return this.loaders.containsKey(key);
}
@Override
public Set<K> keySet() {
return this.loaders.keySet();
}
@Override
public V get(Object key) {
if (!this.loaders.containsKey(key)) {
throw new IllegalArgumentException(
"This map only supports the following keys: " + this.loaders.keySet());
}
return this.loaded.computeIfAbsent((K) key, (k) -> this.loaders.get(k).get());
}
@Override
public V put(K key, V value) {
if (!this.loaders.containsKey(key)) {
throw new IllegalArgumentException(
"This map only supports the following keys: " + this.loaders.keySet());
}
return this.loaded.put(key, value);
}
@Override
public V remove(Object key) {
if (!this.loaders.containsKey(key)) {
throw new IllegalArgumentException(View on GitHub (pinned to 96852e8860)