I’ve got several Spring Boot apps that are deployed as WARs on a Tomcat 9 server. Currently, they either use the Spring Boot Adapter or the Spring Cloud OAuth2 integration and it works quite well. The Securing Applications and Services guide, specifically the Spring Boot Adapter section, reads:
If you plan to deploy your Spring Application as a WAR then you should not use the Spring Boot Adapter and use the dedicated adapter for the application server or servlet container you are using.
It doesn’t give any reasons. So my question is, why is that?