Skip to content

Grails 7 - grails-spring-security Doc - default approch #1173

@arjangch

Description

@arjangch

Expected Behavior

grails-spring-security is using pessimistic approach by default as it says in section 4.1. Pessimistic Lockdown. Which is true I have tested it.

Actual Behaviour

But grails-spring-security Doc section 1.1.3, presumes Public approach by default. Methods in Controller should be lockdown by @Secured(['ROLE_USER'])

Steps To Reproduce

See section 1.1.3 and 4.1 of Spring Security Core Plugin - Reference Documentation

Environment Information

java=21.0.8-zulu
gradle=8.14.3
groovy=4.0.28
grails=7.0.0-RC2

Example Application

No response

Version

7

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions