From 63cf954e0710cf6727657ece845ffd04057b8308 Mon Sep 17 00:00:00 2001 From: Steve Riesenberg Date: Wed, 9 Nov 2022 14:49:15 -0600 Subject: [PATCH] Document SecurityContextRepository default Closes gh-12049 --- docs/modules/ROOT/pages/migration.adoc | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/modules/ROOT/pages/migration.adoc b/docs/modules/ROOT/pages/migration.adoc index 7ec933e06f..151970464c 100644 --- a/docs/modules/ROOT/pages/migration.adoc +++ b/docs/modules/ROOT/pages/migration.adoc @@ -30,6 +30,13 @@ If you are explicitly opting into Spring Security 6's new defaults, the followin include::partial$servlet/architecture/security-context-explicit.adoc[] +=== Multiple SecurityContextRepository + +In Spring Security 5, the default xref:servlet/authentication/persistence.adoc#securitycontextrepository[`SecurityContextRepository`] was `HttpSessionSecurityContextRepository`. + +In Spring Security 6, the default `SecurityContextRepository` is `DelegatingSecurityContextRepository`. +If you configured the `SecurityContextRepository` only for the purpose of updating to 6.0, you can remove it completely. + [[requestcache-query-optimization]] === Optimize Querying of `RequestCache`