Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Boot receipt API: move from local Basic auth to tenant-scoped tokens

Last updated: 30 Sept 20264 min read
tutorial
IntermediateBy AITrove Editorial

A tenant-aware receipt API needs a trusted identity source, a declared permission rule and an owner predicate at the data boundary.

Download Spring source kit

The source kit has two separate systems

The runnable ReceiptApplication uses an in-memory receipt store and local Basic credentials. The JWT tenant fixture is a separate test web context with temporary signing keys and H2 rows. They have not been combined into one deployed API. A migration would replace the local user store, configure a real resource-server issuer and audience, validate tenant membership, then pass an immutable trusted owner to service and repository calls.

Do not switch authentication and assume authorization follows. The filter can require SCOPE_receipt.read while a service checks selected tenant membership; the query must include tenant_id. The H2 query lesson covers row selection. The scope lesson shows that two different 403 decisions can exist in one request.

Define release gates

Store receipts durably with migrations and an index for tenant-scoped access. Test two tenants with the same receipt ID for reads and writes; test token expiry, wrong issuer, wrong audience, missing claim and old signing keys. Check startup and request behavior when the issuer is unavailable. The current local JWT fixture only checks static trusted keys. Before exposing the endpoint, replace fixture credentials and prove that web, method and SQL boundaries agree in the deployed environment.

Checked source

Java
// Target service boundary; the current application does not deploy this flow.
@PreAuthorize("#p0 == authentication.name")
public Receipt read(String trustedTenant, String receiptId) {
    return receiptRepository.findByIdAndTenant(receiptId, trustedTenant);
}

Verification boundary

JwtTenantBoundaryTest.trustedTenantClaimPassesTheMatchingServiceRule and JwtTenantBoundaryTest.scopedQueryExcludesRowsForOtherTenantValues runs in the downloadable Spring source kit. The excerpt is shortened; the kit contains the complete test.

Costs and limits

This is a migration plan backed by a separate local fixture, not a runnable production API. Real identity integration adds provider availability, key cache, revocation and membership costs. A database-backed API also needs pool sizing, migrations and deployed authorization tests.

Common Mistakes

  • Do not deploy the source kit's local Basic credentials.
  • Do not assume a token signature alone grants a tenant row.
  • Do not call the separate JWT fixture the current application's authentication path.

Read next

Spring Boot receipt API project: build, test and inspect the limits, Spring Security JWT tenant principal: map only a validated claim, Spring Security scope versus tenant ownership: two separate decisions, Spring JdbcTemplate tenant predicates: put ownership in the SQL query.

Continue with checked tenant commands

Continue with Spring Boot tenant command API project: assemble the local write path.

spring
spring-boot
tenant-receipt-api-security-plan
Storage details