servletApi() support of Spring Security is great.

I want to inject custom Principal as this:

public interface UserPrincipal extends Principal {
   public Integer getId();
}

@RequestMapping(value = "/")
public ResponseEntity<List<Conversation>> listAfter(UserPrincipal user){
   // implementation
}  

or


@RequestMapping(value = "/")
public ResponseEntity<List<Conversation>> listAfter(UserPrincipalImpl user){
   // implementation
}

Spring has support for injecting Principal instances with the help of ServletRequestMethodArgumentResolver.

It is injecting principal as this:

else if (Principal.class.isAssignableFrom(paramType)) {
    return request.getUserPrincipal();
}

Here is the place where the problem begins. request is here an instance of SecurityContextHolderAwareRequestWrapper. It has an implementation of:

@Override
public Principal getUserPrincipal() {
    Authentication auth = getAuthentication();

    if ((auth == null) || (auth.getPrincipal() == null)) {
        return null;
    }

    return auth;
 }

Because an Authentication is also an Principal. (The only part of spring security I did not like so far. I will ask this a separate question as well.)

This is causing a problem. Because Authentication is a Principal not a UserPrincipal.

How can I resolve this problem? Do I need to implement an authentication which is a UserPrincipal as well? Or should I change HandlerMethodArgumentResolver order a create a custom resolver? (This is not easy for Spring MVC because internal handlers has higher priority.)

As a extra information:

I am using Spring Security M2 and my configuration for AuthenticationManagerBuilder is simply:

@Override
protected vo
Edit
Report