Start Learning
Javaneer
Back to the Spring path
🔐
Module 4

Security

Auth done properly, not bolted on.

Lock down BookVault the right way. The Spring Security filter chain, authentication vs authorization, configuring access rules, password encoding, stateless JWT auth, OAuth2/OpenID Connect, and method-level security.

7 Lessons in this stage1 h 54 min
Start the first lesson

Lessons in this stage

  1. 01

    Spring Security & the Filter Chain

    Intermediate

    How Spring Security intercepts every request with a chain of filters that authenticate and authorize before your controller runs.

    16 min
  2. 02

    Authentication vs Authorization

    Beginner

    Who you are versus what you're allowed to do - the two distinct questions every secure app must answer.

    12 min
  3. 03

    Configuring Access Rules

    Intermediate

    The SecurityFilterChain bean and the lambda DSL: permit, authenticate, and restrict routes by authority.

    18 min
  4. 04

    Users & Password Encoding

    Intermediate

    UserDetailsService, storing users, and why passwords must always be salted and hashed with BCrypt.

    16 min
  5. 05

    Stateless Auth with JWT

    Advanced

    Issue a signed token on login and authenticate every later request from it - no server-side session.

    20 min
  6. 06

    OAuth2 & OpenID Connect

    Advanced

    Delegating authentication to a provider: the resource-server and client roles, and when to use them.

    16 min
  7. 07

    Method Security, CORS & CSRF

    Intermediate

    @PreAuthorize for fine-grained rules, plus what CORS and CSRF are and how Spring handles them.

    16 min