DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk3 min

Spring Data JPA Auditing Outside the HTTP Request

Spring Data JPA auditing can record scheduled and batch work without an HTTP request. Configure AuditorAware to return the actor your audit policy requires.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Spring Data JPA auditing works without an HTTP request. For @CreatedBy and @LastModifiedBy, provide an AuditorAware<T> that returns the intended actor—an authenticated user when available, or a deliberately chosen service or job identity for non-request work. Spring Data does not require the actor to be named system.

How does Spring Data choose the auditor?

When an entity is persisted or updated, Spring Data’s auditing infrastructure asks an AuditorAware<T> implementation who is interacting with the application. The generic type T must match the type used by the entity’s @CreatedBy and @LastModifiedBy fields. The Spring Data JPA Reference Documentation, section “AuditorAware”, describes this as identifying the current “user or system interacting with the application.” It leaves the particular identity and its name to the application.

Spring Security is one possible source, not a requirement that every persistence operation happen during a web request. Its documented example obtains the current Authentication from SecurityContextHolder, checks that it is authenticated, and returns the principal. A scheduled task or batch process can instead resolve its own service or job identity through the same AuditorAware interface.

How should a no-request operation be attributed?

Choose the value based on what the audit record is meant to establish. A job name can identify a scheduled process; a service account can identify an application acting independently; a propagated user identity can preserve who initiated asynchronous work. These choices describe different facts, so a generic system value is appropriate only if it is meaningful under your audit policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Human initiator: Use when the operation must remain attributable to the person who initiated it and that identity is available at the persistence callback.
  • Job or service identity: Use when the process itself is the actor, such as a scheduled task or batch operation.
  • Absent auditor or failure: Decide whether an operation without an actor is permitted. Returning an empty Optional and rejecting an unattributed write are distinct policies; do not let a missing principal silently become an ordinary user.

The identity source must be available when auditing runs. In particular, do not assume request-bound Spring Security state automatically carries over to work running on another thread. If an asynchronous operation needs the initiating user, arrange identity propagation as part of that execution design; otherwise, use the operation’s explicit service or job identity.

How do I enable auditing and supply an auditor?

  1. Enable auditing with @EnableJpaAuditing.
  2. Register AuditingEntityListener for audited entities, using @EntityListeners or ORM configuration.
  3. Provide an AuditorAware<T> bean whose return type matches the actor fields. Spring Data discovers a single provider automatically.
  4. If more than one provider is available, select the intended bean with the auditorAwareRef attribute of @EnableJpaAuditing.

A conceptual outline for a string-valued actor field is:

class ApplicationAuditorAware implements AuditorAware<String> {
    @Override
    public Optional<String> getCurrentAuditor() {
        return currentAuthenticatedUser()
                .or(() -> Optional.of("system"));
    }
}

This is illustrative, not a drop-in implementation: the authentication lookup, principal conversion, and fallback policy must match the application. In particular, falling back to system is wrong if the audit requirement is to preserve the initiating user and that identity should be propagated.

Do timestamp fields need an auditor?

No. @CreatedBy and @LastModifiedBy record who created or last modified an entity; @CreatedDate and @LastModifiedDate record when. You can use the annotations selectively. Timestamp-only auditing does not require an AuditorAware; the reference identifies CurrentDateTimeProvider as the default date-time provider and allows a custom provider.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you verify when the recorded actor is wrong?

  • Confirm that the auditing provider returns the same type as the entity’s actor fields.
  • Check which AuditorAware bean is being used, especially if the application has multiple providers and uses auditorAwareRef.
  • Inspect the identity available when the persistence callback runs; an HTTP request may not exist, and thread-bound security state may not be present on another thread.
  • Confirm that the selected missing-identity policy is intentional: a job identity, an empty auditor, or a failure to write.
  • Keep that policy consistent across application instances and execution paths so the same kind of operation is not attributed differently.

The Spring Data JPA reference cited here identifies itself as version 4.1.1. Check the reference documentation for the version used by your application before relying on version-specific configuration details.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.