spring-projects/spring-security
Documented errors, page 3 of 5. Back to spring-projects/spring-security
| Code / Message | Type | Severity | Tags |
|---|---|---|---|
| Invalid remember-me token (Series/token) mismatch. Implies… | exception | error | remember-me, security, cookie-theft, spring-security |
DigestAuthenticationFilter.incorrectRealm Response realm name ' ' does not match system realm name of | exception | error | spring-security, digest-auth, realm-mismatch, bad-credentials |
| Embedded LDAP server is not provided | exception | error | ldap, configuration, embedded-server, missing-dependency |
| Failed to resolve an unique bean (single or primary) of type | exception | error | native-image, graalvm, cglib, spring-aot |
| One of the patterns in | console | warning | spring-security, url-patterns, deprecation, migration |
| A universal match pattern ('/**') is defined before other… | exception | error | spring-security, filter-chain, ordering, startup-validation |
| Cannot encrypt | exception | error | rsa, encryption, illegal-state, io |
JdbcDaoImpl.noAuthority User has no GrantedAuthority | exception | error | missing-authorities, jdbc, authentication, user-not-found |
SwitchUserFilter.noCurrentUser No current user associated with this request | exception | error | spring-security, switch-user, impersonation, session |
| User credentials have expired | exception | error | ldap, active-directory, credentials-expired, spring-security |
| An error occurred writing the OAuth 2.0 Access Token… | http | error | oauth2, http-message-conversion, serialization |
invalid_redirect_uri Invalid Client Registration: redirect_uris | error_code | error | oauth2, client-registration, redirect-uri, url-validation |
| Failed to obtain DirContext | exception | error | ldap, kerberos, directory-services, network |
| The presented RememberMeAuthenticationToken does not… | exception | error | spring-security, remember-me, shared-key |
| Failed find SHA1PRNG algorithm! | exception | error | spring-security, secure-random, jvm, algorithm-not-found |
invalid_grant Client authentication failed: code_verifier | error_code | error | oauth2, pkce, invalid-grant, spring-authorization-server |
| Object identity ' ' already exists | exception | error | spring-security, acl, duplicate, database |
| Unsupported ProtectionPolicy | exception | error | webauthn, jackson, serialization, enum |
| An error occurred while attempting to decode the Jwt… | exception | error | jwt, malformed-payload, bad-token, spring-security, base64 |
| Invalid algorithm type: N | exception | error | argon2, password-hashing, invalid-enum, crypto |
invalid_key Failed to resolve JWK signing key for client registration | error_code | error | oauth2, jwk, jwt, client-authentication, spring-security |
| Saml2Exception wrapping exception while initializing… | exception | error | saml2, metadata, resolver-initialization, signature-validation, opensaml5 |
| Cpu cost parameter must be > 1 and < 65536. | validation | error | java, spring-security, password-hashing, validation, constructor |
| Detected a Non-hex character at N or N+1 position | exception | error | hex, encoding, spring-security, invalid-characters |
| Failed to select a key since there are multiple for the… | exception | error | jwt, jwk, signing, key-rotation, spring-security |
| method is invalid | validation | error | dpop, http, validation, oauth2, spring-security |
| Cannot configure both a CorsConfigurationSource and a… | exception | error | spring-security, cors, configuration, illegal-state |
| Failed to decode basic authentication token | exception | error | spring-security, http-basic-auth, base64, bad-credentials |
| The requestURI cannot contain encoded slash. Got " +… | exception | error | spring-security, firewall, url-encoding, request-rejected, security |
| Cannot find JSON Converter on the classpath. Add one… | exception | error | spring-security, classpath, json, missing-dependency, jackson |
| Provided token isn't active | exception | error | oauth2, opaque-token, introspection, rfc-7662 |
| Unable to access parameter | exception | error | crypto, algorithm-parameters, cipher, iv, spring-security |
| Unsupported password prefix | validation | error | java, spring-security, ldap, password-hashing |
| Cannot convert to… | exception | error | spring-security, session-management, xml-config, invalid-attribute |
| Cookie contained signature | exception | warning | remember-me, spring-security, signature, tampering |
| Malformed password hash | console | warning | spring-security, argon2, password-encoding, authentication |
| Failed to encode the JWT due to signing error: Failed to… | exception | error | jwt, jwk, signing, key-selection, spring-security |
invalid_destination RelyingPartyRegistration has not been configured with a logout request endpoint | error_code | error | saml2, spring-security, logout, configuration, metadata |
| Object identity not found for ACL | exception | error | spring-security, acl, not-found, update |
| Saml2Exception wrapping exception while signing XMLObject | exception | error | saml2, opensaml, signing, credential |
| An error occurred reading the UserInfo response | http | error | http, json, openid-connect, userinfo |
DigestAuthenticationFilter.nonceCompromised Nonce token compromised | exception | error | spring-security, digest-auth, nonce, tampering, security |
| Exception thrown because of a cycle in the role hierarchy… | exception | critical | role-hierarchy, configuration, startup-failure, cycle |
| The issuer identifier | validation | error | configuration, oauth2, issuer, multi-tenant |
| Unsupported element of type " + element.getTagName() | exception | error | saml2, opensaml, xml-deserialization |
| FilterSecurityInterceptor is configured to reject public… | console | warning | spring-security, login-page, access-control, configuration |
| Invalid encoded Argon2-hash | exception | error | argon2, password-hashing, input-validation, java, spring-security |
AclEntryAfterInvocationProvider.noPermission Authentication has NO permissions to the domain object | exception | error | spring-security, acl, after-invocation, access-denied, permissions |
| An error occurred reading the OAuth 2.0 Access Token… | http | error | oauth2, http-message-conversion, token-response, parsing |
| An error occurred reading the OAuth 2.0 Error | http | error | oauth2, http-message-conversion, json, spring-security |
| Invalid prefix | exception | error | bcrypt, invalid-argument, spring-security, crypto |
| ${ctrl.getErrorStatus()} | exception | error | ldap, password-policy, account-locked, spring-security |
| Encoded password does not look like SCrypt | validation | error | java, spring-security, password-hashing, format-validation, migration |
| Hostname ' ' resolved to will be used on IP address matching | console | warning | spring-security, ip-matching, dns, configuration |
| secretKeyFactoryAlgorithm cannot be null | validation | error | java, spring-security, pbkdf2, null-check |
| Spring Security and Spring MVC must use the same path… | exception | error | spring-security, spring-mvc, path-matching, configuration-conflict |
ConcurrentSessionControlAuthenticationStrategy.exceededAllowed Maximum sessions of for this principal exceeded | exception | warning | spring-security, session, concurrency, authentication |
| Failed to deserialize payload | exception | error | saml2, opensaml, xml-parse, deserialization |
| An error occurred writing the OAuth 2.0 Device… | http | error | oauth2, http-message-conversion, json, spring-security |
| No visible WebSecurityExpressionHandler instance could be… | exception | error | jsp, taglibs, spring-security, authorization, missing-bean |
| A filter chain that matches any request | exception | error | spring-security, filter-chain, security-matcher, configuration |
| Cannot perform login for | exception | error | spring-security, servlet-api, authentication |
| Could not create a default… | exception | error | reactive, session, spring-security, configuration |
| Failed to evaluate expression | exception | error | spel, security, expression-evaluation, authorization |
| Failed to validate the token | exception | error | jwt, signature-validation, oauth2, nimbus |
| Unable to authenticate the PublicKeyCredential | exception | error | webauthn, authentication, http-request, java |
AbstractUserDetailsAuthenticationProvider.disabled User is disabled | exception | error | authentication, reactive, account-disabled, userdetails |
| Could not parse 'Accept' header | http | warning | spring-security, http-headers, content-negotiation |
| Kerberos authentication failed | exception | error | kerberos, jaas, authentication, spring-security |
| Security authorization failed due to | console | warning | security, authorization, access-denied, event-listener |
| Saml2Exception wrapping DecryptionException during… | exception | error | saml2, decryption, encryption-credentials, spring-security |
| An Authentication object was not found in the… | exception | error | websocket, stomp, authentication, spring-security, security-context |
| Found UserDetailsService beans, with names . Global… | console | warning | spring-security, authentication, bean-ambiguity, auto-configuration |
| suffix cannot be empty | exception | error | spring-security, illegal-argument, password-encoding, constructor-validation |
| Failed to encode the JWT due to signing error: Failed to… | exception | error | jwt, jwk, signing, algorithm-mismatch, spring-security |
| User account has expired | exception | error | ldap, active-directory, account-expired, spring-security |
| Encoded password does not look like BCrypt: X | exception | error | bcrypt, invalid-argument-format, spring-security, password-hashing |
internal_validation_error internalValidationError(ex.getMessage()) | error_code | error | saml2, spring-security, internal-error |
JdbcDaoImpl.notFound Username not found | exception | error | user-not-found, jdbc, authentication |
| Missing jwk parameter in JWS Header. | exception | error | dpop, jwt, jwk, oauth2, spring-security |
| Should not happen | exception | error | crypto, cipher, padding, internal-invariant, spring-security |
| Remember-me login has expired | exception | info | remember-me, token-expiry, session, spring-security |
| Unsupported object of type: " +… | exception | error | saml2, opensaml, signature-verification |
| Found incorrect number of instances in application context… | exception | error | spring-security, acl, jsp-taglib, duplicate-bean |
| Unauthenticated or no response token | exception | error | kerberos, spnego, invalid-state |
| User account is locked | exception | error | ldap, active-directory, account-locked, spring-security |
AbstractUserDetailsAuthenticationProvider.expired User account has expired | exception | error | authentication, reactive, account-expired, userdetails |
| doExecute returned null | http | error | java, kerberos, resttemplate, null, response-extractor |
| Duplicate key | exception | error | oauth2, configuration, duplicate-key |
| managerPassword is required if managerDn is supplied | exception | error | ldap, configuration, missing-credentials, spring-security |
| The presented AnonymousAuthenticationToken does not contain… | exception | error | spring-security, anonymous-authentication, shared-key |
| No persistent token found for series id | exception | info | remember-me, token, session, spring-security |
| User is disabled | exception | error | ldap, active-directory, disabled-account, spring-security |
| Given that there is no default password encoder configured… | validation | error | spring-security, password-matching, missing-prefix, legacy-migration |
| You must supply user definitions, either with | exception | error | spring-security, xml-config, bean-definition, missing-config |
DigestAuthenticationFilter.nonceNotNumeric Nonce token should have yielded a numeric first token, but was | exception | error | spring-security, digest-auth, nonce, format-mismatch |
| Empty Password | exception | error | ldap, authentication, empty-password, input-validation |
| Amount of performance parameters invalid | exception | error | argon2, password-hashing, input-validation, java, spring-security |
DigestAuthenticationFilter.missingMandatory Missing mandatory digest value; received header | exception | error | spring-security, digest-auth, http-header, bad-credentials |
| The request was rejected because the header: \"" + name + "… | exception | error | spring-security, http-firewall, request-rejected, header-injection |