This is a regression of #8471 (which was resolved in d4b52a3): according to the resolution of that issue, the health actuator endpoint should check if the supplied "role" is actually an authority (not prefixed with "ROLE_") when deciding whether or not to show health-check details. This appears to have been fixed in the 1.5.2 release, but as of 2.1.7 (and in the latest HealthWebEndpointResponseMapper as of today, if I am reading it correctly), only roles are allowed, not authorities.
|
private boolean isUserInRole(SecurityContext securityContext) { |