We should deprecate authorization logic that uses FilterInvocation in favor of using RequestAuthorizationContext. A few examples:
- SecurityExpressionHandler<FilterInvocation>in favor of- SecurityExpressionHandler<RequestAuthorizationContext>
- FilterInvocationExpressionRoot(might change to- HttpServletRequestExpressionRoot) in favor of- WebSecurityExpressionRoot
- DefaultWebSecurityExpressionHandlerin favor of- DefaultHttpSecurityExpressionHandler
Related gh-17673