spring-projects/spring-security · error · IllegalArgumentException

Unsupported element of type " + element.getClass()

Error message

Unsupported element of type " + element.getClass()

What it means

ExpressionTemplateSecurityAnnotationScanner.merge only supports Class or Method annotated elements. When given any other AnnotatedElement type (e.g. Field, Package, Parameter) it throws IllegalArgumentException because template-based security annotation scanning is only defined for classes and methods.

Solutions

  1. Restrict the element passed to the scanner to Class or Method
  2. If you need field/parameter-level security, implement a custom SecurityAnnotationScanner that handles those types
  3. Check upstream code (e.g. custom MethodSecurityMetadataSource) and filter unsupported elements before calling merge

Example fix

// before
scanner.merge(field, targetClass);
// after
if (element instanceof Class || element instanceof Method) {
    scanner.merge(element, targetClass);
}
Defensive patterns

Strategy: type-guard

Validate before calling

if (!(element instanceof Class) && !(element instanceof Method)) { return null; }

Type guard

boolean isSupportedElement(AnnotatedElement e) { return e instanceof Class || e instanceof Method; }

Prevention

When it happens

Trigger: Passing a non-Class/non-Method element (Field, Constructor, Parameter, etc.) to the scanner's merge method — typically via a custom pointcut or security-metadata source that hands the scanner arbitrary reflective elements.

Common situations: Custom AuthorizeReactiveMethodInterceptor / authorization metadata lookup over fields or parameters; framework code that scans annotations on unusual element types.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/b886de1e06359e5d. Report an issue: GitHub.

Appendix: source

Thrown at core/src/main/java/org/springframework/security/core/annotation/ExpressionTemplateSecurityAnnotationScanner.java:115

	}

	@Override
	@Nullable MergedAnnotation<A> merge(AnnotatedElement element, @Nullable Class<?> targetClass) {
		if (element instanceof Parameter parameter) {
			MergedAnnotation<A> annotation = this.unique.merge(parameter, targetClass);
			if (annotation == null) {
				return null;
			}
			return resolvePlaceholders(annotation);
		}
		if (element instanceof Method method) {
			MergedAnnotation<A> annotation = this.unique.merge(method, targetClass);
			if (annotation == null) {
				return null;
			}
			return resolvePlaceholders(annotation);
		}
		throw new IllegalArgumentException("Unsupported element of type " + element.getClass());
	}

	private MergedAnnotation<A> resolvePlaceholders(MergedAnnotation<A> mergedAnnotation) {
		if (this.templateDefaults == null) {
			return mergedAnnotation;
		}
		if (mergedAnnotation.getMetaSource() == null) {
			return mergedAnnotation;
		}
		PropertyPlaceholderHelper helper = new PropertyPlaceholderHelper("{", "}", null, null,
				this.templateDefaults.isIgnoreUnknown());
		Map<String, Object> properties = new HashMap<>(mergedAnnotation.asMap());
		Map<String, String> metaAnnotationProperties = extractMetaAnnotationProperties(mergedAnnotation);
		for (Map.Entry<String, Object> annotationProperty : mergedAnnotation.asMap().entrySet()) {
			if (!(annotationProperty.getValue() instanceof String expression)) {
				continue;
			}
			String value = helper.replacePlaceholders(expression, metaAnnotationProperties::get);

View on GitHub (pinned to 96852e8860)