With the default role prefix, hasRole('EDITOR') checks for a granted authority named ROLE_EDITOR rather than EDITOR.
Spring Security roles and authorities: check the actual granted string
The two tokens behave differently
The local method-security test first authenticates a reviewer with authority EDITOR. Calling the managed service is denied. Replacing it with ROLE_EDITOR permits the same method. The result is from a proxied service in a Spring context, not a string comparison inside the method body.
An application can customize its role prefix, so document that configuration and test the actual authorities emitted by its authentication converter. For a claim that already carries an exact permission such as receipt:approve, hasAuthority can be clearer than a role shortcut. The JWT lesson checks token trust and scopes before any business authorization.
A role is not record ownership
A reviewer role may permit an operation class but still should not modify every tenant's receipt. Tenant-scoped writes need a trusted owner and a scoped database predicate. Method security can protect a service call, yet a same-class call through this bypasses proxy advice; test through the managed bean.
Checked source
@PreAuthorize("hasRole('EDITOR')")
public String approve() { return "approved"; }Verification boundary
RoleAuthorityContractTest.roleRuleExpectsTheConfiguredRolePrefix runs in the downloadable Spring source kit. The excerpt omits imports and surrounding setup; the kit contains the complete tests.
Costs and limits
The test checks one default-prefix rule and two local authentication objects. It does not verify a JWT converter, remote issuer, HTTP filter chain, custom role hierarchy or database ownership.
Common Mistakes
- Do not pass EDITOR when the configured rule expects ROLE_EDITOR.
- Do not assume hasRole implies row-level tenant permission.
- Do not test the plain target object when the rule is applied by a proxy.
Read next
Spring method authorization: test the proxied service boundary, Spring method security: reject a cross-tenant receipt mutation, Spring Security JWT resource server: validate trust before checking scope.
Continue with checked tenant security
Continue with Spring Security scope versus tenant ownership: two separate decisions.
