Spring Boot 4.1.1 config behavior surprises developer behind security linter
A developer maintaining spring-config-guard, a static-analysis tool that flags Spring Boot security misconfigurations, began testing actual runtime behavior in Spring Boot 4.1.1 after finding that documentation alone was insufficient. Testing revealed that /actuator/configprops gives a more accurate post-binding view of resolved properties than /actuator/env, which only shows raw values per source without indicating which wins. Endpoint availability depends on both exposure and access settings, meaning management.endpoints.web.exposure.include=* alone does not expose heapdump or shutdown, which carry restricted access by default. However, setting endpoints.access.default=unrestricted alongside a wildcard include does expose both, including heapdump, which can leak secrets from application memory. These findings prompted the developer to update the linter's internal model to reflect actual Spring Boot resolution logic rather than assumed documentation behavior.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in