spring-projects/spring-security · error · IllegalArgumentException
Unsupported element of type " + element.getClass()
Error message
Unsupported element of type " + element.getClass()
What it means
ExpressionTemplateSecurityAnnotationScanner.merge only supports Class or Method annotated elements. When given any other AnnotatedElement type (e.g. Field, Package, Parameter) it throws IllegalArgumentException because template-based security annotation scanning is only defined for classes and methods.
Solutions
- Restrict the element passed to the scanner to Class or Method
- If you need field/parameter-level security, implement a custom SecurityAnnotationScanner that handles those types
- Check upstream code (e.g. custom MethodSecurityMetadataSource) and filter unsupported elements before calling merge
Example fix
// before
scanner.merge(field, targetClass);
// after
if (element instanceof Class || element instanceof Method) {
scanner.merge(element, targetClass);
} Defensive patterns
Strategy: type-guard
Validate before calling
if (!(element instanceof Class) && !(element instanceof Method)) { return null; } Type guard
boolean isSupportedElement(AnnotatedElement e) { return e instanceof Class || e instanceof Method; } Prevention
- Only pass Class or Method elements to security annotation scanners
- Filter reflective elements before invoking the scanner
- Don't attempt field/parameter-level security scanning with this scanner
When it happens
Trigger: Passing a non-Class/non-Method element (Field, Constructor, Parameter, etc.) to the scanner's merge method — typically via a custom pointcut or security-metadata source that hands the scanner arbitrary reflective elements.
Common situations: Custom AuthorizeReactiveMethodInterceptor / authorization metadata lookup over fields or parameters; framework code that scans annotations on unusual element types.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- Unsupported element of type
- Please ensure there is one unique annotation of type
- Access Denied
- Access is denied
- Access is denied
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/b886de1e06359e5d.
Report an issue: GitHub.
Appendix: source
Thrown at core/src/main/java/org/springframework/security/core/annotation/ExpressionTemplateSecurityAnnotationScanner.java:115
}
@Override
@Nullable MergedAnnotation<A> merge(AnnotatedElement element, @Nullable Class<?> targetClass) {
if (element instanceof Parameter parameter) {
MergedAnnotation<A> annotation = this.unique.merge(parameter, targetClass);
if (annotation == null) {
return null;
}
return resolvePlaceholders(annotation);
}
if (element instanceof Method method) {
MergedAnnotation<A> annotation = this.unique.merge(method, targetClass);
if (annotation == null) {
return null;
}
return resolvePlaceholders(annotation);
}
throw new IllegalArgumentException("Unsupported element of type " + element.getClass());
}
private MergedAnnotation<A> resolvePlaceholders(MergedAnnotation<A> mergedAnnotation) {
if (this.templateDefaults == null) {
return mergedAnnotation;
}
if (mergedAnnotation.getMetaSource() == null) {
return mergedAnnotation;
}
PropertyPlaceholderHelper helper = new PropertyPlaceholderHelper("{", "}", null, null,
this.templateDefaults.isIgnoreUnknown());
Map<String, Object> properties = new HashMap<>(mergedAnnotation.asMap());
Map<String, String> metaAnnotationProperties = extractMetaAnnotationProperties(mergedAnnotation);
for (Map.Entry<String, Object> annotationProperty : mergedAnnotation.asMap().entrySet()) {
if (!(annotationProperty.getValue() instanceof String expression)) {
continue;
}
String value = helper.replacePlaceholders(expression, metaAnnotationProperties::get);View on GitHub (pinned to 96852e8860)