advancedScenario Questions
Scenario 26: A method annotated with @Async that reads SecurityContextHolder.getContext().getAuthentication() gets null instead of the logged-in user.
By default, SecurityContextHolder uses a ThreadLocal strategy, so the authenticated context set on the original request thread isn't automatically visible to a new thread spawned by @Async. Fix by switching the holder strategy to MODE_INHERITABLETHREADLOCAL, or by explicitly capturing and propagating the SecurityContext into the async task yourself.
Ready to master this question?
Generate a complete walkthrough — background, the full answer in plain language, a working code example explained line by line, a real-world scenario, common mistakes, and how this same question gets asked in different ways.
Sign in to generate a response