Don't let security be an afterthought. Spring Security in Action, Second Edition is your vital companion to robust, secure applications that are protected right from the first line of code.
Spring Security in Action, Second Edition is a revised version of the bestselling original, fully updated for Spring Boot 3 and Oauth2/OpenID Connect.
In Spring Security in Action, Second Edition you will learn essential security skills including how to:
Implement and customize authentication and authorization
Set up all components of an OAuth2/OpenID Connect system
Utilize CRSF and CORS configurations
Secure Spring reactive applications
Write tests for security configurations
Whether you’re a beginner or a pro, Spring Security in Action, Second Edition teaches you how to secure your Java applications from the ground up. Author Laurențiu Spilcă distills his years of experience as a skilled Java and Spring developer into an indispensable guide to everything security—from authentication and authorization, to testing security configurations. This new edition covers the latest patterns for application-level security in Spring apps, demonstrating how Spring Security simplifies every step of the security process.
About the technology
Spring Security makes it much, much easier to secure enterprise-scale Java applications. This powerful framework integrates with Spring apps end to end, with “secure by design” principles and ready-to-use features that help you implement robust authorization and authentication and protect against data theft and intrusions. And like everything else in the Spring ecosystem, it’s free, open source, and backed by the awesome team at VMWare.
About the reader
For experienced Java and Spring developers.
About the author
Laurențiu Spilcă is a skilled Java and Spring developer and an experienced technology instructor. He is also the author of Mann
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
# Spring Security in Action, Second Edition — Reading Guide
## 【One-Line Pitch】
A practical, hands-on guide to implementing robust application-level security in Spring Boot 3 applications, covering everything from basic authentication to full OAuth2/OpenID Connect systems. Essential reading for experienced Java and Spring developers who want to move beyond "security as an afterthought" and build protection into their code from the first line.
## 【Book Arc】
- **Opening (~0%–9%)**: Introduces the security landscape and why Spring Security matters, positioning it as the standard framework for securing Spring applications. Covers alternatives like Apache Shiro and establishes the core principle that Spring Security is a toolset—developers must understand and apply it correctly.
- **Early (~9%–25%)**: Walks through the fundamental authentication architecture: the filter chain, `UserDetailsService`, `PasswordEncoder`, and the security context. Readers learn to override Spring Boot's default in-memory credentials and configure their own users, then move into custom `AuthenticationProvider` implementations.
- **Early–Middle (~25%–38%)**: Deep dive into user management contracts—`UserDetails`, `GrantedAuthority`, `UserDetailsManager`—with practical implementations including `InMemoryUserDetailsManager`, `JdbcUserDetailsManager`, and `LdapUserDetailsManager`, plus guidance on when to write custom implementations.
- **Middle (~38%–47%)**: Explores password encoding strategies in depth (including SCrypt and `DelegatingPasswordEncoder`), the Spring Security Crypto module for encryption, and begins the critical topic of HTTP filters as the foundation of web application security.
- **Late (~47% onward)**: Covers advanced topics including custom filter chains, authorization configuration at endpoint level, CSRF and CORS, OAuth2/OpenID Connect setup, reactive application security, and testing security configurations (detailed in chapter 18).
## 【Key Takeaways】
- **Spring Security is a framework, not a magic wand** (Early): The framework provides the infrastructure, but developers must understand and configure it properly—it doesn't automatically secure data at rest or in flight. This mindset shapes every subsequent chapter.
- **The authentication flow follows a clear chain of responsibilities** (Early): `AuthenticationProvider` orchestrates authentication, delegating to `UserDetailsService` for user management and `PasswordEncoder` for password handling, with results stored in the security context for the duration of the request.
- **Default configurations are for proofs of concept, not production** (Early): Spring Boot's default in-memory user with a randomly generated UUID password demonstrates the dependency works but should never ship to production. Overriding these defaults is the first real task in any project.
- **Separate user management from authentication logic** (Early): Even when implementing custom `AuthenticationProvider` logic, you should still use `UserDetailsService` and `PasswordEncoder` beans rather than inlining credential checks—this follows the architecture Spring Security designed.
- **The `UserDetails` contract is the foundation of user representation** (Early–Middle): Understanding `UserDetails`, `GrantedAuthority`, and `UserDetailsManager` interfaces lets you choose between built-in implementations (in-memory, JDBC, LDAP) or write custom ones when none fit your system.
- **Password encoding is not optional** (Middle): The `PasswordEncoder` both encodes and verifies passwords, with multiple strategies available—from simple no-op implementations for demos to SCrypt with configurable CPU cost, memory cost, key length, and salt length parameters.
- **`DelegatingPasswordEncoder` solves migration headaches** (Middle): When authentication must support multiple encoding strategies simultaneously, this delegating tool routes to the appropriate encoder—essential for evolving legacy systems.
- **Encryption utilities are built into Spring Security Crypto** (Middle): The `Encryptors` factory provides byte and text encryptors with different strength levels (AES-CBC vs. AES-GCM), plus a no-op variant for performance testing without encryption overhead.
## 【Reading Tips】
- **Skim the opening chapters (1–2) if you're experienced**: The alternatives comparison (Apache Shiro) and basic setup are useful context but move quickly—the real value starts with overriding default configurations and understanding the authentication architecture.
- **Deep-read chapters 3–4 on user management and password encoding**: These are the most transferable skills. The `UserDetailsService` implementations (in-memory, JDBC, LDAP) and `PasswordEncoder` strategies appear throughout the rest of the book and in real projects.
- **Pay special attention to the custom `AuthenticationProvider` example**: The book shows both the "right way" (using `UserDetailsService` and `PasswordEncoder`) and the "quick way" (inline credential checks), making the architectural reasoning explicit.
- **Don't skip the filter chain material**: It appears around the 47% mark and is foundational for understanding how Spring Security intercepts requests—this knowledge is assumed in later chapters on CSRF, CORS, and OAuth2.
- **Note that testing is deferred to chapter 18**: The author deliberately separates testing discussion to keep chapters focused, but mentions this early—if testing is your priority, you may want to jump ahead or at least be aware of where it lives.
## 【Coverage Limits】
The excerpts primarily cover the foundational material through roughly the midpoint of the book (authentication architecture, user management, password encoding, and the beginning of filter chains). Detailed coverage of OAuth2/OpenID Connect, CSRF/CORS configuration, reactive security, and testing (chapters 12–18) is mentioned in the book's overview but not detailed in the available excerpts.
##
Excerpt 1
d Spring developer and an experienced technology instructor. He is also the author of Mann SECOND EDITION Lauren`tiu Spilca˘ Foreword by Joe Grandja M A N N...
ssword (usually using an encryption or a hashing algorithm) ¡ Verifies if the password matches an existing encoding Even if it’s not as obvious as the UserDe...
e of these so that you have an idea of what we’ll be doing. In this chapter, as well as chapters 4 and 5, we’ll discuss these interfaces in more detail, to...
text() or Encryptors.delux(). Besides these methods to cre- ate encryptors, there is also a method that returns a dummy TextEncryptor, which doesn’t encrypt...
field declared using the AuthenticationProvider interface. Spring recognizes the Authentication Provider as an interface (which is an abstraction). However...
privileges. The getAuthorities() method returns the collec- tion of GrantedAuthority instances. In listing 7.2, you can review this method in the UserDetail...
specific symbols or characters.” For these scenarios, you need to use a more powerful expression like a regex. You can use regexes to represent any format ...
, `identifier` VARCHAR(45) NULL, `token` TEXT NULL, PRIMARY KEY (`id`)); We use Spring Data with a JPA implementation to connect to the database, so ...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Spring Security in Action, Second Edition (Laurențiu Spilcǎ)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Spring Security in Action, Second Edition (Laurențiu Spilcǎ)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment