spring-projects/spring-security · error · IllegalArgumentException

This map only supports the following keys: " +…

Error message

This map only supports the following keys: " + this.loaders.keySet()

What it means

SecurityReactorContextConfiguration uses an internal read-only map view (with a computeIfAbsent loader cache) that only accepts keys corresponding to registered loaders. get() with an unknown key throws IllegalArgumentException listing the supported keys. Callers are expected to only look up keys produced by keySet().

Solutions

  1. Only query keys obtained from the map's keySet() (the security context loader keys Spring Security registers)
  2. Use the public Reactor Context API (context.get(SecurityContext.class) style accessors) instead of touching the internal map
  3. Align Spring Security versions so the loader key classes match those registered

Example fix

// before
Object v = securityLoaders.get(myArbitraryKey);
// after
if (securityLoaders.keySet().contains(myArbitraryKey)) {
    Object v = securityLoaders.get(myArbitraryKey);
}
Defensive patterns

Strategy: type-guard

Validate before calling

if (map != null && map.keySet().contains(key)) {
    V value = map.get(key);
}

Type guard

static <K,V> boolean isSupportedKey(Map<K,V> map, Object key) {
    return map != null && map.keySet().contains(key);
}

Try / catch

try {
    value = loadersMap.get(key);
} catch (IllegalArgumentException e) {
    if (e.getMessage().startsWith("This map only supports the following keys")) {
        value = null; // key not managed by security context loaders
    } else throw e;
}

Prevention

When it happens

Trigger: Calling get(key) on this map with a key not present in loaders.keySet(); passing a Reactor context key of the wrong type or from a different security module; external code treating the map as a general-purpose Map.

Common situations: Custom WebFlux/Reactor code reading the security Reactor context with hand-built keys; version mismatches where the loader key class changed between Spring Security versions; reflection-based access to the internal map.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/f7bdad470aaf494e. Report an issue: GitHub.

Appendix: source

Thrown at config/src/main/java/org/springframework/security/config/annotation/web/configuration/SecurityReactorContextConfiguration.java:238

		@Override
		public boolean isEmpty() {
			return this.loaders.isEmpty();
		}

		@Override
		public boolean containsKey(Object key) {
			return this.loaders.containsKey(key);
		}

		@Override
		public Set<K> keySet() {
			return this.loaders.keySet();
		}

		@Override
		public V get(Object key) {
			if (!this.loaders.containsKey(key)) {
				throw new IllegalArgumentException(
						"This map only supports the following keys: " + this.loaders.keySet());
			}
			return this.loaded.computeIfAbsent((K) key, (k) -> this.loaders.get(k).get());
		}

		@Override
		public V put(K key, V value) {
			if (!this.loaders.containsKey(key)) {
				throw new IllegalArgumentException(
						"This map only supports the following keys: " + this.loaders.keySet());
			}
			return this.loaded.put(key, value);
		}

		@Override
		public V remove(Object key) {
			if (!this.loaders.containsKey(key)) {
				throw new IllegalArgumentException(

View on GitHub (pinned to 96852e8860)