Annotation Type AuthenticationPrincipal


@Retention(CLASS) @Target(PARAMETER) public @interface AuthenticationPrincipal

Binds a handler parameter to the principal of whoever the request is from: the UserDetails the user store returned at sign-in, usually.

@GetMapping("/me")
public Map me(@AuthenticationPrincipal UserDetails user) {
    ...
}

The parameter is null when the principal is not of the declared type -- which includes a request nobody signed in for, whose principal is the text anonymousUser. Declare an Authentication parameter instead to get the authentication itself.