Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Spring Data JPA auditing works without an HTTP request. For @CreatedBy and @LastModifiedBy, provide an AuditorAware<T> that returns the intended actor—an authenticated user when available, or a deliberately chosen service or job identity for non-request work. Spring Data does not require the actor to be named system.
How does Spring Data choose the auditor?
When an entity is persisted or updated, Spring Data’s auditing infrastructure asks an AuditorAware<T> implementation who is interacting with the application. The generic type T must match the type used by the entity’s @CreatedBy and @LastModifiedBy fields. The Spring Data JPA Reference Documentation, section “AuditorAware”, describes this as identifying the current “user or system interacting with the application.” It leaves the particular identity and its name to the application.
Spring Security is one possible source, not a requirement that every persistence operation happen during a web request. Its documented example obtains the current Authentication from SecurityContextHolder, checks that it is authenticated, and returns the principal. A scheduled task or batch process can instead resolve its own service or job identity through the same AuditorAware interface.
How should a no-request operation be attributed?
Choose the value based on what the audit record is meant to establish. A job name can identify a scheduled process; a service account can identify an application acting independently; a propagated user identity can preserve who initiated asynchronous work. These choices describe different facts, so a generic system value is appropriate only if it is meaningful under your audit policy.
#1 Best Overall
- Human initiator: Use when the operation must remain attributable to the person who initiated it and that identity is available at the persistence callback.
- Job or service identity: Use when the process itself is the actor, such as a scheduled task or batch operation.
- Absent auditor or failure: Decide whether an operation without an actor is permitted. Returning an empty
Optionaland rejecting an unattributed write are distinct policies; do not let a missing principal silently become an ordinary user.
The identity source must be available when auditing runs. In particular, do not assume request-bound Spring Security state automatically carries over to work running on another thread. If an asynchronous operation needs the initiating user, arrange identity propagation as part of that execution design; otherwise, use the operation’s explicit service or job identity.
How do I enable auditing and supply an auditor?
- Enable auditing with
@EnableJpaAuditing. - Register
AuditingEntityListenerfor audited entities, using@EntityListenersor ORM configuration. - Provide an
AuditorAware<T>bean whose return type matches the actor fields. Spring Data discovers a single provider automatically. - If more than one provider is available, select the intended bean with the
auditorAwareRefattribute of@EnableJpaAuditing.
A conceptual outline for a string-valued actor field is:
class ApplicationAuditorAware implements AuditorAware<String> {
@Override
public Optional<String> getCurrentAuditor() {
return currentAuthenticatedUser()
.or(() -> Optional.of("system"));
}
}
This is illustrative, not a drop-in implementation: the authentication lookup, principal conversion, and fallback policy must match the application. In particular, falling back to system is wrong if the audit requirement is to preserve the initiating user and that identity should be propagated.
Do timestamp fields need an auditor?
No. @CreatedBy and @LastModifiedBy record who created or last modified an entity; @CreatedDate and @LastModifiedDate record when. You can use the annotations selectively. Timestamp-only auditing does not require an AuditorAware; the reference identifies CurrentDateTimeProvider as the default date-time provider and allows a custom provider.
Rank #3
What should you verify when the recorded actor is wrong?
- Confirm that the auditing provider returns the same type as the entity’s actor fields.
- Check which
AuditorAwarebean is being used, especially if the application has multiple providers and usesauditorAwareRef. - Inspect the identity available when the persistence callback runs; an HTTP request may not exist, and thread-bound security state may not be present on another thread.
- Confirm that the selected missing-identity policy is intentional: a job identity, an empty auditor, or a failure to write.
- Keep that policy consistent across application instances and execution paths so the same kind of operation is not attributed differently.
The Spring Data JPA reference cited here identifies itself as version 4.1.1. Check the reference documentation for the version used by your application before relying on version-specific configuration details.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




