๐Ÿ” Spring Security

Core โ†’ Advanced

  • Architecture: SecurityFilterChain, DelegatingFilterProxy, filter order, SecurityContext
  • Authentication vs authorization; AuthenticationManager, providers, UserDetailsService
  • Password hashing (bcrypt/argon2), PasswordEncoder
  • Sessions vs stateless JWT; CSRF (when it matters), CORS
  • Method security: @PreAuthorize, custom permission evaluators
  • OAuth2 / OIDC: roles (resource owner, client, authorization server, resource server)
    • Authorization Code + PKCE flow ยท client credentials (service-to-service) ยท refresh tokens
    • JWT structure, signing (RS256), JWKS, validation, expiry, revocation strategies
  • Resource server (oauth2ResourceServer().jwt()), OAuth2 client/login
  • Keycloak as the IdP (or Spring Authorization Server)
  • Multi-tenancy, API keys, mTLS between services
  • Passkeys/WebAuthn (awareness), one-time tokens
  • Testing: @WithMockUser, jwt() request post-processors

๐Ÿงช Labs (๐ŸŸข warm-up โ†’ ๐ŸŸก core โ†’ ๐Ÿ”ด hard โ†’ โšซ boss)

  • ๐ŸŸข Log the security filter chain; send a bad JWT and trace the rejection
  • ๐ŸŸก Keycloak org-per-tenant + roles + a JWT resource server
  • ๐Ÿ”ด API keys (hashed, prefix lookup, rotation) as a custom AuthenticationProvider
  • ๐Ÿ”ด Postgres RLS driven by the authenticated tenant; a cross-tenant attack suite
  • โšซ OAuth2 client for connectors (GitHub/Slack) with encrypted token storage + refresh

๐Ÿง  Cognitive tasks

  • Draw Auth Code + PKCE from memory; explain what each parameter prevents
  • Threat model (STRIDE) for API keys

๐Ÿ›ฐ๏ธ Orbit integration

  • Multi-tenancy for orbit-api; the OAuth connectors in orbit-tools

Go deeper

โš™๏ธ Spring Internals ยท ๐Ÿ”’ Security Engineering

Resources

  • Spring Security in Action 2e (Spilcฤƒ) โญ ยท Spring Security reference docs
  • OAuth 2 in Action ยท oauth.net ยท jwt.io ยท API Security in Action (Madden) Related: Security Engineering