Spring Authorization Server
Beyond the certificate: run your own OAuth2/OIDC issuer.
An optional, senior-level module beyond the Spring certificate. Stop hand-rolling HS256 tokens and run a real OAuth2/OpenID Connect provider with Spring Authorization Server: the authorization-code + PKCE flow, JWT vs. opaque tokens, client credentials for service-to-service, and federated login - turning BookVault's shortcut into a proper issuer other apps can trust.
Lessons in this stage
- 01
OAuth2 & OIDC, Precisely
IntermediateThe four OAuth2 roles, what a grant actually is, and how OpenID Connect adds identity on top - the vocabulary you need before running your own server.
14 min - 02
Running an Authorization Server
AdvancedWhat Spring Authorization Server is, a minimal setup, and registering clients - the difference between issuing tokens and merely validating them.
15 min - 03
Authorization Code & PKCE
AdvancedThe authorization-code flow step by step, why the implicit flow is dead, and how PKCE secures public clients like SPAs and mobile apps.
16 min - 04
Tokens: JWT vs. Opaque
AdvancedAccess tokens, refresh tokens, and ID tokens; the JWT-vs-opaque trade-off; JWK key rotation; and customizing claims so resource servers can trust them.
15 min - 05
Service-to-Service & Federation
AdvancedThe client-credentials grant for machine-to-machine calls, federated (social) login, and pointing BookVault's resource server at your own issuer.
14 min