We should deprecate authorization logic that uses FilterInvocation in favor of using RequestAuthorizationContext. A few examples:
SecurityExpressionHandler<FilterInvocation> in favor of SecurityExpressionHandler<RequestAuthorizationContext>
FilterInvocationExpressionRoot (might change to HttpServletRequestExpressionRoot) in favor of WebSecurityExpressionRoot
DefaultWebSecurityExpressionHandler in favor of DefaultHttpSecurityExpressionHandler
Related gh-17673