Security
Auth done properly, not bolted on.
Lock down BookVault the right way. The Spring Security filter chain, authentication vs authorization, configuring access rules, password encoding, stateless JWT auth, OAuth2/OpenID Connect, and method-level security.
Lessons in this stage
- 01
Spring Security & the Filter Chain
IntermediateHow Spring Security intercepts every request with a chain of filters that authenticate and authorize before your controller runs.
16 min - 02
Authentication vs Authorization
BeginnerWho you are versus what you're allowed to do - the two distinct questions every secure app must answer.
12 min - 03
Configuring Access Rules
IntermediateThe SecurityFilterChain bean and the lambda DSL: permit, authenticate, and restrict routes by authority.
18 min - 04
Users & Password Encoding
IntermediateUserDetailsService, storing users, and why passwords must always be salted and hashed with BCrypt.
16 min - 05
Stateless Auth with JWT
AdvancedIssue a signed token on login and authenticate every later request from it - no server-side session.
20 min - 06
OAuth2 & OpenID Connect
AdvancedDelegating authentication to a provider: the resource-server and client roles, and when to use them.
16 min - 07
Method Security, CORS & CSRF
Intermediate@PreAuthorize for fine-grained rules, plus what CORS and CSRF are and how Spring handles them.
16 min