Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Security roles and authorities: check the actual granted string

Last updated: 30 Sept 20264 min read
tutorial
IntermediateBy AITrove Editorial

With the default role prefix, hasRole('EDITOR') checks for a granted authority named ROLE_EDITOR rather than EDITOR.

Download Spring source kit

The two tokens behave differently

The local method-security test first authenticates a reviewer with authority EDITOR. Calling the managed service is denied. Replacing it with ROLE_EDITOR permits the same method. The result is from a proxied service in a Spring context, not a string comparison inside the method body.

An application can customize its role prefix, so document that configuration and test the actual authorities emitted by its authentication converter. For a claim that already carries an exact permission such as receipt:approve, hasAuthority can be clearer than a role shortcut. The JWT lesson checks token trust and scopes before any business authorization.

A role is not record ownership

A reviewer role may permit an operation class but still should not modify every tenant's receipt. Tenant-scoped writes need a trusted owner and a scoped database predicate. Method security can protect a service call, yet a same-class call through this bypasses proxy advice; test through the managed bean.

Checked source

Java
@PreAuthorize("hasRole('EDITOR')")
public String approve() { return "approved"; }

Verification boundary

RoleAuthorityContractTest.roleRuleExpectsTheConfiguredRolePrefix runs in the downloadable Spring source kit. The excerpt omits imports and surrounding setup; the kit contains the complete tests.

Costs and limits

The test checks one default-prefix rule and two local authentication objects. It does not verify a JWT converter, remote issuer, HTTP filter chain, custom role hierarchy or database ownership.

Common Mistakes

  • Do not pass EDITOR when the configured rule expects ROLE_EDITOR.
  • Do not assume hasRole implies row-level tenant permission.
  • Do not test the plain target object when the rule is applied by a proxy.

Read next

Spring method authorization: test the proxied service boundary, Spring method security: reject a cross-tenant receipt mutation, Spring Security JWT resource server: validate trust before checking scope.

Continue with checked tenant security

Continue with Spring Security scope versus tenant ownership: two separate decisions.

spring
spring-boot
role-authority-prefix
Storage details