advancedScenario Questions

Scenario 26: A method annotated with @Async that reads SecurityContextHolder.getContext().getAuthentication() gets null instead of the logged-in user.

By default, SecurityContextHolder uses a ThreadLocal strategy, so the authenticated context set on the original request thread isn't automatically visible to a new thread spawned by @Async. Fix by switching the holder strategy to MODE_INHERITABLETHREADLOCAL, or by explicitly capturing and propagating the SecurityContext into the async task yourself.

Ready to master this question?

Generate a complete walkthrough — background, the full answer in plain language, a working code example explained line by line, a real-world scenario, common mistakes, and how this same question gets asked in different ways.

Sign in to generate a response

Next Step

Continue to Scenario 27: After scaling from one server instance to three behind a load balancer, users report being logged out mid-session at random.← Back to all Spring Security questions