Update docs on Principal controller method arguments

Closes gh-26791
This commit is contained in:
Rossen Stoyanchev
2021-04-21 17:28:14 +01:00
parent d25ae4b02c
commit 42a23098de

View File

@@ -2003,6 +2003,12 @@ and others) and is equivalent to `required=false`.
| `java.security.Principal`
| Currently authenticated user -- possibly a specific `Principal` implementation class if known.
Note that this argument is not resolved eagerly, if it is annotated in order to allow a custom resolver to resolve it
before falling back on default resolution resolution via `HttpServletRequest#getUserPrincipal`.
For example, the Spring Security `Authentication` implements `Principal` and would be injected as such via
`HttpServletRequest#getUserPrincipal`, unless it is also annotated with `@AuthenticationPrincipal` in which case it
is resolved by a custom Spring Security resolver through `Authentication#getPrincipal`.
| `HttpMethod`
| The HTTP method of the request.