jamesfredley commented on issue #15898:
URL: https://github.com/apache/grails-core/issues/15898#issuecomment-5946729284

   This is a servlet-API mismatch, not a Grails 8 defect.
   
   The failure is `filterInvocationInterceptorDeregistrationBean` trying to put 
a `FilterSecurityInterceptor` into `FilterRegistrationBean.filter` when that 
property is `javax.servlet.Filter`. Grails 6.1.1 uses `javax.servlet`. Spring 
Security 6's interceptor implements `jakarta.servlet.Filter`, so Spring cannot 
convert it. Adding `spring-security-web` or `spring-security-config` next to 
the Grails plugin pulls that Jakarta type onto a `javax` application. The 
Grails 7 upgrade notes say the same thing: Spring Security 6 uses 
`jakarta.servlet` instead of `javax.servlet`.
   
   https://docs.grails.org/latest/guide/upgrading.html
   
   On `8.0.x` the plugin's own `FilterSecurityInterceptor` implements 
`jakarta.servlet.Filter`, and `SpringSecurityBeanFactoryPostProcessor` 
registers the deregistration bean with Spring Boot's `FilterRegistrationBean`, 
which takes that same type. That class arrived in `33ccb41faf` (2026-07-05, 
"Pull forward Grails Spring Security 8.x changes"). It is in `v8.0.0-RC1` and 
`v8.0.0-RC2`, not in `v7.2.4` or `v8.0.0-M1`. Use the Spring Security plugin 
that matches the Grails line instead of adding a standalone Spring Security 
release. Closing as not a core defect.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to