jamesfredley commented on issue #15898: URL: https://github.com/apache/grails-core/issues/15898#issuecomment-5946729284
This is a servlet-API mismatch, not a Grails 8 defect. The failure is `filterInvocationInterceptorDeregistrationBean` trying to put a `FilterSecurityInterceptor` into `FilterRegistrationBean.filter` when that property is `javax.servlet.Filter`. Grails 6.1.1 uses `javax.servlet`. Spring Security 6's interceptor implements `jakarta.servlet.Filter`, so Spring cannot convert it. Adding `spring-security-web` or `spring-security-config` next to the Grails plugin pulls that Jakarta type onto a `javax` application. The Grails 7 upgrade notes say the same thing: Spring Security 6 uses `jakarta.servlet` instead of `javax.servlet`. https://docs.grails.org/latest/guide/upgrading.html On `8.0.x` the plugin's own `FilterSecurityInterceptor` implements `jakarta.servlet.Filter`, and `SpringSecurityBeanFactoryPostProcessor` registers the deregistration bean with Spring Boot's `FilterRegistrationBean`, which takes that same type. That class arrived in `33ccb41faf` (2026-07-05, "Pull forward Grails Spring Security 8.x changes"). It is in `v8.0.0-RC1` and `v8.0.0-RC2`, not in `v7.2.4` or `v8.0.0-M1`. Use the Spring Security plugin that matches the Grails line instead of adding a standalone Spring Security release. Closing as not a core defect. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
