Expected Behavior The default behaviour of the AuthenticationSuccessHandler and AuthenticationFailureHandlers should be acessible, so that they can be extended and/or composed without having to copy-paste them from the current source code.

Current Behavior In OAuth2AuthorizationEndpointFilter, for example, both handlers are private method references, with no getters defined either.

Context I wanted to change the error page handler when the redirectUri cannot be used. This was easily possible in the previous implementation.

Comment From: jgrandja

Related spring-projects/spring-authorization-server#1557

Comment From: jgrandja

This issue was transferred from spring-projects/spring-authorization-server#2195