Security
Auth done properly, not bolted on.
Lock down BookVault the right way. The Spring Security filter chain, authentication vs authorization, configuring access rules, password encoding, stateless JWT auth, OAuth2/OpenID Connect, and method-level security.
Lessons in this stage
- 01
Spring Security & the Filter Chain
IntermediateHow Spring Security intercepts every request with a chain of filters that authenticate and authorize before your controller runs.
16 min - 02
Authentication vs Authorization
BeginnerWho you are versus what you're allowed to do - the two distinct questions every secure app must answer.
12 min - 03
Configuring Access Rules
IntermediateThe SecurityFilterChain bean and the lambda DSL: permit, authenticate, and restrict routes by authority.
18 min - 04
Users & Password Encoding
IntermediateUserDetailsService, storing users, and why passwords must always be salted and hashed with BCrypt.
16 min - 05
Stateless Auth with JWT
AdvancedIssue a signed token on login and authenticate every later request from it - no server-side session.
20 min - 06
OAuth2 & OpenID Connect
AdvancedDelegating authentication to a provider: the resource-server and client roles, and when to use them.
16 min - 07
Method Security, CORS & CSRF
Intermediate@PreAuthorize for fine-grained rules, plus what CORS and CSRF are and how Spring handles them.
16 min
Ready to test yourself?
Take the stage assessment to check your mastery. Pass it to earn a stage badge toward your Javaneer certificate.