Spring Security applies authentication, authorization and browser protections at request boundaries.
Learning roadmap
Read the contract, run the source-kit checks, and inspect a rejected input before extending the application. This subject covers Spring and Spring Boot together; Java language lessons remain in their own subject.
Prerequisites
Use Java object ownership, interfaces, exceptions and Maven builds before the framework-specific lessons.
Section lessons
- Spring Security filter chain: authentication, CSRF and request order
- Spring PasswordEncoder: salted verification rather than reversible storage
- Spring method authorization: test the proxied service boundary
- Spring Security JWT resource server: validate trust before checking scope
- Spring method authorization: reject a cross-tenant read
- Spring method security: reject a cross-tenant receipt mutation
- Spring Security roles and authorities: check the actual granted string
- Spring Security JWT tenant principal: map only a validated claim
- Spring Security scope versus tenant ownership: two separate decisions
- Spring JWT tenant claims: reject missing or malformed ownership before conversion
- Spring JdbcTemplate tenant predicates: put ownership in the SQL query
- Spring tenant headers: prove they cannot override a signed identity
- Spring Security bearer POST and CSRF: define the credential boundary
- Spring file uploads: discard the supplied filename before writing
- Spring Security health probes: expose only the health path
Continue learning
Boot Foundations, Spring Core, Web APIs, Data & Transactions, Testing, Production, Exercises, Quizzes, Projects.
Request authorization and browser state
- Spring Security request matchers: order rules and cover the fallback
- Spring Security CSRF: protect cookie-authenticated writes
OAuth2 browser and service clients
- Spring Security OAuth2 login: callback, identity and browser session
- Spring OAuth2 client credentials: acquire and reuse a service token
GraphQL tenant boundaries
Spring Cloud boundary lessons
Spring AI boundary lessons
- Spring AI prompt injection: treat retrieved text as data, not authority
- Spring AI tools: authorize each requested action after model selection
Token and browser-session boundaries
- Spring resource server JWT: validate both issuer and intended audience
- Spring Security 401 versus 403: authentication and access are separate failures
- Spring Security login session: rotate the identifier at authentication
Run an OAuth2 authorization server
- Spring Authorization Server, OAuth2 client and resource server: three trust roles
- Spring Authorization Server JDBC state: clients, grants and consent across restarts
- Spring Authorization Server grants: PKCE for public clients, credentials for services
Shared sessions and nested query authorization
- Spring Session Redis across replicas: shared login state has a Redis failure boundary
- Spring Session cookie policy: SameSite, Secure and the reverse proxy
- Spring Session principal index: invalidate one operator's sessions safely
- Spring GraphQL batch loader tenant scope: never key a shared cache by row ID alone
Gateway and STOMP identity boundaries
- Spring Cloud Gateway rate limits: derive the key from authenticated identity
- Spring WebSocket STOMP identity: authenticate the handshake, authorize destinations
Outbound token ownership
Method-level authorization
- Spring method security: authorization advice runs through the bean proxy
- Spring @PostAuthorize: denial happens after the method has run
SAML identity and authority
- Spring Security SAML relying party: align registration, ACS and metadata
- Spring Security SAML validation: signatures, audience and clock window
- Spring Security SAML attributes: map identity to local authority
SAML logout, sessions and certificate rollover
- Spring Security SAML logout: local session versus single logout
- Spring SAML session revocation: closing the browser is not deprovisioning
- Spring SAML certificate rollover: overlap trust without accepting unknown keys
Security maintenance and request boundaries
- Spring Resource Server JWT key rotation: overlap keys across token lifetime
- Spring password hash upgrade after a verified login
- Spring SecurityContext handoff to a bounded async executor
- Spring Security CORS preflight: evaluate origin before authentication
Security chain and token boundaries
- Spring Security multiple filter chains: match the whole request surface
- Spring Security stateless APIs: remove session and saved-request assumptions
- Spring JWT authority mapping: convert a trusted claim into one deliberate namespace
- Spring JWT clock skew: bound tolerance without extending token trust blindly
- Spring Security SPA CSRF: refresh the token after login and logout
- Spring opaque-token introspection: budget the authorization-server dependency
- Spring Security CSP rollout: enforce tested asset rules at the response edge
- Spring method security ownership bean: authorize before the service changes state
