KamoCRM

Declare security matchers explicitly before the next build breaks startup

Fixkamolos
Shipped
8 ஆகஸ்ட், 2026 அன்று 6:21 PM UTC
Author
Kamo
Commit
6bb2dd6

kamo-shared-library 1.5.0 was republished today with spring-ws-core as a new transitive dependency, so Spring Boot now auto-registers a second servlet (MessageDispatcherServlet at /services/*). With two mappable servlets, Spring Security 6 will not guess whether a bare requestMatchers("/x/**") is MVC or Ant and throws while building the filter chain -- the application never starts. The running pod is from 25h ago and predates the republish, so it has no spring-ws and starts fine; the break arrives with the next build. BillingService already hit this in production (its deploys had been failing since 2026-07-03), and EmailService documents the same trap in ResourceServerConfig. Behaviour is unchanged: the chain still permits everything.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing