Skip to content
AITroveRead. Build. Understand.

Security

Authentication and browser boundaries

Spring Security applies authentication, authorization and browser protections at request boundaries.

Learning roadmap

Read the contract, run the source-kit checks, and inspect a rejected input before extending the application. This subject covers Spring and Spring Boot together; Java language lessons remain in their own subject.

Prerequisites

Use Java object ownership, interfaces, exceptions and Maven builds before the framework-specific lessons.

Section lessons

Continue learning

Boot Foundations, Spring Core, Web APIs, Data & Transactions, Testing, Production, Exercises, Quizzes, Projects.

Request authorization and browser state

OAuth2 browser and service clients

GraphQL tenant boundaries

Spring Cloud boundary lessons

Spring AI boundary lessons

Token and browser-session boundaries

Run an OAuth2 authorization server

Shared sessions and nested query authorization

Gateway and STOMP identity boundaries

Outbound token ownership

Method-level authorization

SAML identity and authority

SAML logout, sessions and certificate rollover

Security maintenance and request boundaries

Security chain and token boundaries

Curriculum

Inspect the state boundary and run its checked fixture.

  1. 1Spring method authorization: test the proxied service boundary

Follow the input contract, inspect failures and run the checked source.

  1. 1Spring Security JWT resource server: validate trust before checking scope

Read the contract, run the checked fixture and inspect the rejected path.

  1. 1Spring method authorization: reject a cross-tenant read

Run the source-kit fixture and inspect its rejected boundary.

  1. 1Spring method security: reject a cross-tenant receipt mutation

Run the source-kit test and inspect the rejected case.

  1. 1Spring Security roles and authorities: check the actual granted string

Trace a tenant-scoped command from token to committed rows.

  1. 1Spring Security bearer POST and CSRF: define the credential boundary

Check schema execution, authorization, costs and verification scope.

  1. 1Spring GraphQL tenant reads: scope every resolver before returning a record

Read the application contract and its unverified integration boundary.

  1. 1Spring Cloud Gateway tenant routing: authenticate at the edge and enforce again at the service

Follow the operation through failure, recovery and linked tests.

  1. 1Spring OAuth2 client tokens: bind the authorized client to the intended caller and host

Storage details