๐ Spring Security
Core โ Advanced
- Architecture:
SecurityFilterChain,DelegatingFilterProxy, filter order,SecurityContext - Authentication vs authorization;
AuthenticationManager, providers,UserDetailsService - Password hashing (bcrypt/argon2),
PasswordEncoder - Sessions vs stateless JWT; CSRF (when it matters), CORS
- Method security:
@PreAuthorize, custom permission evaluators - OAuth2 / OIDC: roles (resource owner, client, authorization server, resource server)
- Authorization Code + PKCE flow ยท client credentials (service-to-service) ยท refresh tokens
- JWT structure, signing (RS256), JWKS, validation, expiry, revocation strategies
- Resource server (
oauth2ResourceServer().jwt()), OAuth2 client/login - Keycloak as the IdP (or Spring Authorization Server)
- Multi-tenancy, API keys, mTLS between services
- Passkeys/WebAuthn (awareness), one-time tokens
- Testing:
@WithMockUser,jwt()request post-processors
๐งช Labs (๐ข warm-up โ ๐ก core โ ๐ด hard โ โซ boss)
- ๐ข Log the security filter chain; send a bad JWT and trace the rejection
- ๐ก Keycloak org-per-tenant + roles + a JWT resource server
- ๐ด API keys (hashed, prefix lookup, rotation) as a custom
AuthenticationProvider - ๐ด Postgres RLS driven by the authenticated tenant; a cross-tenant attack suite
- โซ OAuth2 client for connectors (GitHub/Slack) with encrypted token storage + refresh
๐ง Cognitive tasks
- Draw Auth Code + PKCE from memory; explain what each parameter prevents
- Threat model (STRIDE) for API keys
๐ฐ๏ธ Orbit integration
- Multi-tenancy for orbit-api; the OAuth connectors in orbit-tools
Go deeper
โ๏ธ Spring Internals ยท ๐ Security Engineering
Resources
- Spring Security in Action 2e (Spilcฤ) โญ ยท Spring Security reference docs
- OAuth 2 in Action ยท oauth.net ยท jwt.io ยท API Security in Action (Madden) Related: Security Engineering