Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Spring Security 3 lets you express authorization rules as Spring Expression Language (SpEL) Boolean expressions for both web requests and method calls. For URL rules in the XML namespace, enable expressions on <http> with use-expressions="true"; for method rules, enable pre/post annotations with <global-method-security pre-post-annotations="enabled"/>.

How Spring Security 3 expressions work

Spring Security 3.0 added SpEL authorization alongside configuration attributes and access-decision voters. An expression is evaluated against a security-specific root object, so available values and functions depend on whether the rule applies to a web request or a method invocation. Expressions are useful when a role check alone is not enough—for example, when access depends on the caller’s identity, a request property, or a method argument.

Common expressions include hasRole, hasAnyRole, principal, authentication, permitAll, denyAll, isAnonymous(), isRememberMe(), isAuthenticated(), and isFullyAuthenticated(). Spring Security 3.2 documentation also describes authority aliases and hasPermission forms for checking a target object or a target identifier and type. See the Spring Security 3.0 expression-based access control reference and the Spring Security 3.2 reference for version-specific details.

Secure URLs with XML namespace expressions

Set use-expressions="true" on the <http> element. Each matching <intercept-url> rule’s access value must then be a SpEL expression that evaluates to a Boolean decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
<http use-expressions="true">
  <intercept-url pattern="/admin*"
      access="hasRole('admin') and hasIpAddress('192.168.1.0/24')"/>
</http>

In this example, the caller needs the admin role and must come from the stated IP range. hasIpAddress is specific to web authorization. The web expression root, WebSecurityExpressionRoot, also exposes the current HttpServletRequest as request.

When the XML namespace configures these rules, Spring Security adds a WebExpressionVoter to the AccessDecisionManager. If you configure web authorization without the namespace, register the voter with your AccessDecisionManager yourself; otherwise the expression may not participate in the access decision. The 3.0 expression reference documents the namespace behavior and web-specific expression root.

Secure method calls with annotations

Enable Spring Security 3 pre- and post-invocation annotations in XML with:

<global-method-security pre-post-annotations="enabled"/>

Use the annotation that matches when the decision should happen and what data it needs:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Annotation When it evaluates Useful expression value
@PreAuthorize Before the method runs Method arguments, authentication, and the principal
@PostAuthorize After the method returns returnObject
@PreFilter Before invocation, filtering an input collection filterObject for the current element
@PostFilter After invocation, filtering a returned collection filterObject for the current element

Use method arguments in a pre-authorization rule

@PreAuthorize is appropriate when the permission depends on the object being passed to the method. For example, a rule can check whether the current caller has permission to administer the supplied contact, or compare that contact’s name with authentication.name. Argument names are available when the code is compiled with debug information. Spring Security 3.2 also documents parameter-name discovery through DefaultSecurityParameterNameDiscoverer and the @P annotation.

Check a result or filter a collection

@PostAuthorize can authorize a returned object by referring to it as returnObject. @PreFilter and @PostFilter instead remove collection elements that do not satisfy the expression; the current element is named filterObject. This is useful for per-object checks, but filtering is distinct from rejecting an entire invocation: choose the annotation based on whether the intended outcome is a denied call or a filtered collection.

Rank #4
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Understand what hasPermission requires

Writing hasPermission in an expression does not by itself define domain-object permissions. In the Spring Security 3 model, the expression is connected to the ACL module through the application context; the ACL integration and its configuration are needed for those checks. Consult the 3.0 reference before relying on object-permission expressions.

Diagnose method rules that appear ineffective

  • Check how the object was created. Method security applies to instances created as Spring beans in the application context where method security is enabled. The Spring Security 3.2 reference says instances created outside Spring—for example, with new—require AspectJ if they are to be secured.
  • Check argument-name discovery. If an expression refers to a named method parameter, ensure the name is discoverable from compilation metadata or a supported discovery approach such as the 3.2 @P option.
  • Check the web voter for non-namespace configuration. Web expression rules configured outside the XML namespace need a WebExpressionVoter registered with the AccessDecisionManager.

These are concrete configuration checks, not an exhaustive list of possible causes; a rule’s result also depends on the expression, the applicable security root, and the authorization configuration. The Spring Security 3.2 reference describes method-security scope and parameter discovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Move from Spring Security 3 to current method security

Current Spring Security documentation recommends replacing legacy @EnableGlobalMethodSecurity and XML <global-method-security> configuration with @EnableMethodSecurity and <method-security>. The replacement enables pre/post annotations by default and uses AuthorizationManager internally. If the old configuration enabled only another mode, such as secured, explicitly disable pre/post behavior during migration if that remains the intended policy.

Custom subclasses of DefaultMethodSecurityExpressionHandler may also need adjustment if they override the older authentication-based evaluation-context method; current documentation notes the supplier-based evaluation-context method. Review the current method-security documentation before carrying custom handlers or old XML forward.

Keep this migration separate from how legacy web authorization is represented. The current authorization overview says that as of Spring Security 7, AccessDecisionManager, AccessDecisionVoter, and related Access API types are in the spring-security-access legacy module, described as a migration aid for older applications. See the current authorization architecture overview; do not treat that status as a change to the historical Spring Security 3 setup.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 3
Bestseller No. 4
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.