Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Laurentiu Spilca

Rating No ratings yet

Spring Security in Action shows you how to prevent cross-site scripting and request forgery attacks before they do damage. You’ll start with the basics, simulating password upgrades and adding multiple types of authorization. As your skills grow, you'll adapt Spring Security to new architectures and create advanced OAuth2 configurations. By the time you're done, you'll have a customized Spring Security configuration that protects against threats both common and extraordinary. Summary While creating secure applications is critically important, it can also be tedious and time-consuming to stitch together the required collection of tools. For Java developers, the powerful Spring Security framework makes it easy for you to bake security into your software from the very beginning. Filled with code samples and practical examples, Spring Security in Action teaches you how to secure your apps from the most common threats, ranging from injection attacks to lackluster monitoring. In it, you'll learn how to manage system users, configure secure endpoints, and use OAuth2 and OpenID Connect for authentication and authorization. About the technology Security is non-negotiable. You rely on Spring applications to transmit data, verify credentials, and prevent attacks. Adopting "secure by design" principles will protect your network from data theft and unauthorized intrusions. About the book Spring Security in Action shows you how to prevent cross-site scripting and request forgery attacks before they do damage. You’ll start with the basics, simulating password upgrades and adding multiple types of authorization. As your skills grow, you'll adapt Spring Security to new architectures and create advanced OAuth2 configurations. By the time you're done, you'll have a customized Spring Security configuration that protects against threats both common and extraordinary. What's inside • Encoding passwords and authenticating users • Securing endpoints • Automating security testing • Setting

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on guide to baking security into Java/Spring applications from the ground up, walking you from basic authentication and authorization through to OAuth2 and OpenID Connect. Best for Spring developers who want to use Spring Security correctly rather than copy-paste configurations they don't understand. 【Book Arc】 - **Opening (~0%–10%)**: Frames security as a layered, cross-cutting concern and surveys common web vulnerabilities (injection, sensitive-data exposure, XSS, CSRF) so you know what you're defending against. - **Early (~10%–30%)**: Gets a first Spring Security app running — default configuration, HTTP Basic, and overriding defaults with custom `UserDetailsService` and `PasswordEncoder` beans. - **Early–Middle (~30%–45%)**: Deepens user management with the `UserDetails`, `UserDetailsService`, and `UserDetailsManager` contracts, plus password encoding strategies including `DelegatingPasswordEncoder`. - **Middle (~45%–60%)**: Explains the authentication architecture — `AuthenticationProvider`, `SecurityContext`, and the `SecurityContextHolder` threading strategies (THREADLOCAL, INHERITABLETHREADLOCAL, GLOBAL). - **Late (~60%–85%)**: Moves to authorization, endpoint protection, and adapting Spring Security to new architectures; excerpts do not cover the exact chapter breakdown here. - **Ending (~85%–100%)**: Advanced OAuth2 and OpenID Connect configuration, plus automated security testing, culminating in a customized configuration. (Excerpts do not cover these chapters in detail.) 【Key Takeaways】 - **Security is layered, and Spring Security handles the application layer** (Opening): it protects the app's environment, data, and the system it runs on — not networking or storage, which have their own practices. - **Know the common vulnerabilities before configuring defenses** (Opening): injection attacks (SQL, LDAP, XPath, OS command) and sensitive-data exposure are recurring, high-impact mistakes that good configuration prevents. - **Spring Security's defaults are a starting point, not a destination** (Early): a default project proves dependencies are wired correctly; real apps override user management and authorization explicitly. - **Separate user management from authorization configuration** (Early): splitting `UserDetailsService`/`PasswordEncoder` beans from `WebSecurityConfigurerAdapter` keeps responsibilities clean and projects readable. - **The `UserDetails` contract describes a user; `UserDetailsService` describes how to obtain one** (Early–Middle): `UserDetailsManager` extends this with create/change/delete, and implementations include in-memory, JDBC, and LDAP variants. - **`DelegatingPasswordEncoder` lets you migrate password schemes safely** (Middle): it picks an encoder based on a hash prefix, defaulting to a chosen implementation (e.g., BCrypt) when no prefix is present. - **Authentication is pluggable via `AuthenticationProvider`** (Middle): when username/password isn't enough (SMS codes, fingerprints, key files), you implement custom providers rather than fighting the framework. - **`SecurityContextHolder` threading strategy matters for async code** (Middle): THREADLOCAL is the default; INHERITABLETHREADLOCAL copies context to `@Async` threads, and manually created threads need explicit context copying. 【Reading Tips】 - **Deep-read the early chapters on `UserDetails`/`UserDetailsService`/`PasswordEncoder`** — these contracts underpin everything later, and the book builds on them repeatedly. - **Skim the vulnerability survey if you already know OWASP basics**, but don't skip it entirely; it frames why each configuration choice exists. - **Pay close attention to the `SecurityContextHolder` threading section** — it's a common source of subtle bugs in async and reactive applications. - **Treat the OAuth2/OpenID Connect material as the payoff** — read it after the authentication architecture clicks, not before. - **Run the code samples**; the book is example-driven, and the cURL/Base64 walkthroughs are meant to be typed, not just read. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering roughly the first half of the book; the authorization, architecture-adaptation, OAuth2/OpenID Connect, and testing chapters are referenced but not detailed in the source material.
Excerpt 1
gainst threats both common and extraordinary. What's inside • Encoding passwords and authenticating users • Securing endpoints • Automating security testing...
View in text
Excerpt 2
e app can use resources from the resource server. Figure 1.13 The OAuth 2 authorization flow with password grant type. To execute an action requested by the...
View in text
Excerpt 3
ng and maintainability. For example, the name isAccountNon- Expired() looks like a double negation, and at first sight, might create con- fusion. But analyze...
View in text
Excerpt 4
a common approach as each request has an individual thread. MODE_INHERITABLETHREADLOCAL—Similar to MODE_THREADLOCAL but also instructs Spring Security to cop...
View in text
Excerpt 5
UserDetailsService contract. For this, create a class named JpaUserDetailsService. This class uses the UserRepository we create in step 3 to obtain the detai...
View in text
Excerpt 6
ccur, one which usually creates confusion among developers. NOTE If multiple filters have the same position, the order in which they are called is not define...
View in text
Excerpt 7
mple.org The browser doesn’t allow the content from example.org because it is cross-domain. Figure 10.13 Even if the example.org page is loaded in an iframe...
View in text
Excerpt 8
client. The client uses the token to access user resources. In the second step, the user sends the OTP to prove they really are who they claim to be, and aft...
View in text
Tags
AI categories
JavaCybersecuritySoftware
ISBN: 1617297739
Publish Year: 2020
Language: English
Pages: 560
File Format: PDF
File Size: 13.6 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…