Start Learning
Javaneer
Back to the Spring path
🔐
Module 4

Security

Auth done properly, not bolted on.

Lock down BookVault the right way. The Spring Security filter chain, authentication vs authorization, configuring access rules, password encoding, stateless JWT auth, OAuth2/OpenID Connect, and method-level security.

7 Lessons in this stage1 h 54 min
Start the first lesson

Lessons in this stage

  1. 01

    Spring Security & the Filter Chain

    Intermediate

    How Spring Security intercepts every request with a chain of filters that authenticate and authorize before your controller runs.

    16 min
  2. 02

    Authentication vs Authorization

    Beginner

    Who you are versus what you're allowed to do - the two distinct questions every secure app must answer.

    12 min
  3. 03

    Configuring Access Rules

    Intermediate

    The SecurityFilterChain bean and the lambda DSL: permit, authenticate, and restrict routes by authority.

    18 min
  4. 04

    Users & Password Encoding

    Intermediate

    UserDetailsService, storing users, and why passwords must always be salted and hashed with BCrypt.

    16 min
  5. 05

    Stateless Auth with JWT

    Advanced

    Issue a signed token on login and authenticate every later request from it - no server-side session.

    20 min
  6. 06

    OAuth2 & OpenID Connect

    Advanced

    Delegating authentication to a provider: the resource-server and client roles, and when to use them.

    16 min
  7. 07

    Method Security, CORS & CSRF

    Intermediate

    @PreAuthorize for fine-grained rules, plus what CORS and CSRF are and how Spring handles them.

    16 min

Ready to test yourself?

Take the stage assessment to check your mastery. Pass it to earn a stage badge toward your Javaneer certificate.

Take the assessment