Spring Security applies authentication, authorization and browser protections at request boundaries.
Learning roadmap
Read the contract, run the source-kit checks, and inspect a rejected input before extending the application. This subject covers Spring and Spring Boot together; Java language lessons remain in their own subject.
Prerequisites
Use Java object ownership, interfaces, exceptions and Maven builds before the framework-specific lessons.
Section lessons
- Spring Security filter chain: authentication, CSRF and request order
- Spring PasswordEncoder: salted verification rather than reversible storage
- Spring method authorization: test the proxied service boundary
- Spring Security JWT resource server: validate trust before checking scope
- Spring method authorization: reject a cross-tenant read
- Spring method security: reject a cross-tenant receipt mutation
- Spring Security roles and authorities: check the actual granted string
- Spring Security JWT tenant principal: map only a validated claim
- Spring Security scope versus tenant ownership: two separate decisions
- Spring JWT tenant claims: reject missing or malformed ownership before conversion
- Spring JdbcTemplate tenant predicates: put ownership in the SQL query
- Spring tenant headers: prove they cannot override a signed identity
- Spring Security bearer POST and CSRF: define the credential boundary
- Spring file uploads: discard the supplied filename before writing
- Spring Security health probes: expose only the health path
Continue learning
Boot Foundations, Spring Core, Web APIs, Data & Transactions, Testing, Production, Exercises, Quizzes, Projects.
