Vaadin 24 LTS @AnonymousAllowed enforcement change breaks Spring Security test integration
0 reputation · 11 Dec 2025, 19:43 UTC
Context
Vaadin 24 LTS tightened enforcement of @AnonymousAllowed so that navigation now requires explicit permission even when a mock user exists in the Spring Security test context. This change affects integration tests that rely on @SpringBootTest with @WithMockUser to exercise views without production credentials.
Problem
When the Spring Security filter chain is not fully initialized in a test slice, views annotated only with @AnonymousAllowed still redirect to the login page. Vaadin TestBench offers a bypass by setting a test‑specific VaadinSession attribute, yet this mechanism is not automatically wired to Spring Security's test user. The framework currently leaves it unresolved whether the UI tier should honor @WithMockUser automatically or require developers to populate VaadinSecurityContext manually in tests.
Open questions
- Should Vaadin Flow automatically synchronize Spring Security's test authentication into
VaadinSecurityContextduring@SpringBootTestexecution? - Is there a supported configuration that makes
@AnonymousAllowedbehave consistently between Vaadin 23 LTS and 24 LTS without modifying test code? - What is the recommended pattern for integration tests that need both Spring Security method security (
@PreAuthorize) and Vaadin navigation authorization to align in a test slice?