diff --git a/web/src/main/java/org/springframework/security/web/authentication/AbstractAuthenticationProcessingFilter.java b/web/src/main/java/org/springframework/security/web/authentication/AbstractAuthenticationProcessingFilter.java
index a2db490781..9d71972066 100644
--- a/web/src/main/java/org/springframework/security/web/authentication/AbstractAuthenticationProcessingFilter.java
+++ b/web/src/main/java/org/springframework/security/web/authentication/AbstractAuthenticationProcessingFilter.java
@@ -161,7 +161,8 @@ public abstract class AbstractAuthenticationProcessingFilter extends GenericFilt
* to perform the authentication. There are then three possible outcomes:
*
* - An Authentication object is returned.
- * The configured {link SessionAuthenticationStrategy} will be invoked followed by the
+ * The configured {@link SessionAuthenticationStrategy} will be invoked (to handle any session-related behaviour
+ * such as creating a new session to protect against session-fixation attacks) followed by the invocation of
* {@link #successfulAuthentication(HttpServletRequest, HttpServletResponse, Authentication)
* successfulAuthentication} method
* - An AuthenticationException occurs during authentication.
@@ -273,8 +274,6 @@ public abstract class AbstractAuthenticationProcessingFilter extends GenericFilt
* Default behaviour for successful authentication.
*
* - Sets the successful Authentication object on the {@link SecurityContextHolder}
- * - Invokes the configured {@link SessionAuthenticationStrategy} to handle any session-related behaviour
- * (such as creating a new session to protect against session-fixation attacks).
* - Informs the configured RememberMeServices of the successful login
* - Fires an {@link InteractiveAuthenticationSuccessEvent} via the configured
* ApplicationEventPublisher
@@ -298,8 +297,6 @@ public abstract class AbstractAuthenticationProcessingFilter extends GenericFilt
* Default behaviour for successful authentication.
*
* - Sets the successful Authentication object on the {@link SecurityContextHolder}
- * - Invokes the configured {@link SessionAuthenticationStrategy} to handle any session-related behaviour
- * (such as creating a new session to protect against session-fixation attacks).
* - Informs the configured RememberMeServices of the successful login
* - Fires an {@link InteractiveAuthenticationSuccessEvent} via the configured
* ApplicationEventPublisher