A tenant-aware receipt API needs a trusted identity source, a declared permission rule and an owner predicate at the data boundary.
Spring Boot receipt API: move from local Basic auth to tenant-scoped tokens
The source kit has two separate systems
The runnable ReceiptApplication uses an in-memory receipt store and local Basic credentials. The JWT tenant fixture is a separate test web context with temporary signing keys and H2 rows. They have not been combined into one deployed API. A migration would replace the local user store, configure a real resource-server issuer and audience, validate tenant membership, then pass an immutable trusted owner to service and repository calls.
Do not switch authentication and assume authorization follows. The filter can require SCOPE_receipt.read while a service checks selected tenant membership; the query must include tenant_id. The H2 query lesson covers row selection. The scope lesson shows that two different 403 decisions can exist in one request.
Define release gates
Store receipts durably with migrations and an index for tenant-scoped access. Test two tenants with the same receipt ID for reads and writes; test token expiry, wrong issuer, wrong audience, missing claim and old signing keys. Check startup and request behavior when the issuer is unavailable. The current local JWT fixture only checks static trusted keys. Before exposing the endpoint, replace fixture credentials and prove that web, method and SQL boundaries agree in the deployed environment.
Checked source
// Target service boundary; the current application does not deploy this flow.
@PreAuthorize("#p0 == authentication.name")
public Receipt read(String trustedTenant, String receiptId) {
return receiptRepository.findByIdAndTenant(receiptId, trustedTenant);
}Verification boundary
JwtTenantBoundaryTest.trustedTenantClaimPassesTheMatchingServiceRule and JwtTenantBoundaryTest.scopedQueryExcludesRowsForOtherTenantValues runs in the downloadable Spring source kit. The excerpt is shortened; the kit contains the complete test.
Costs and limits
This is a migration plan backed by a separate local fixture, not a runnable production API. Real identity integration adds provider availability, key cache, revocation and membership costs. A database-backed API also needs pool sizing, migrations and deployed authorization tests.
Common Mistakes
- Do not deploy the source kit's local Basic credentials.
- Do not assume a token signature alone grants a tenant row.
- Do not call the separate JWT fixture the current application's authentication path.
Read next
Spring Boot receipt API project: build, test and inspect the limits, Spring Security JWT tenant principal: map only a validated claim, Spring Security scope versus tenant ownership: two separate decisions, Spring JdbcTemplate tenant predicates: put ownership in the SQL query.
Continue with checked tenant commands
Continue with Spring Boot tenant command API project: assemble the local write path.
