Spring Security in Action shows you how to prevent cross-site scripting and request forgery attacks before they do damage. You’ll start with the basics, simulating password upgrades and adding multiple types of authorization. As your skills grow, you'll adapt Spring Security to new architectures and create advanced OAuth2 configurations. By the time you're done, you'll have a customized Spring Security configuration that protects against threats both common and extraordinary.
Summary
While creating secure applications is critically important, it can also be tedious and time-consuming to stitch together the required collection of tools. For Java developers, the powerful Spring Security framework makes it easy for you to bake security into your software from the very beginning. Filled with code samples and practical examples, Spring Security in Action teaches you how to secure your apps from the most common threats, ranging from injection attacks to lackluster monitoring. In it, you'll learn how to manage system users, configure secure endpoints, and use OAuth2 and OpenID Connect for authentication and authorization.
About the technology
Security is non-negotiable. You rely on Spring applications to transmit data, verify credentials, and prevent attacks. Adopting "secure by design" principles will protect your network from data theft and unauthorized intrusions.
About the book
Spring Security in Action shows you how to prevent cross-site scripting and request forgery attacks before they do damage. You’ll start with the basics, simulating password upgrades and adding multiple types of authorization. As your skills grow, you'll adapt Spring Security to new architectures and create advanced OAuth2 configurations. By the time you're done, you'll have a customized Spring Security configuration that protects against threats both common and extraordinary.
What's inside
• Encoding passwords and authenticating users
• Securing endpoints
• Automating security testing
• Setting
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A hands-on guide to baking security into Java/Spring applications from the ground up, walking you from basic authentication and authorization through to OAuth2 and OpenID Connect. Best for Spring developers who want to use Spring Security correctly rather than copy-paste configurations they don't understand.
【Book Arc】
- **Opening (~0%–10%)**: Frames security as a layered, cross-cutting concern and surveys common web vulnerabilities (injection, sensitive-data exposure, XSS, CSRF) so you know what you're defending against.
- **Early (~10%–30%)**: Gets a first Spring Security app running — default configuration, HTTP Basic, and overriding defaults with custom `UserDetailsService` and `PasswordEncoder` beans.
- **Early–Middle (~30%–45%)**: Deepens user management with the `UserDetails`, `UserDetailsService`, and `UserDetailsManager` contracts, plus password encoding strategies including `DelegatingPasswordEncoder`.
- **Middle (~45%–60%)**: Explains the authentication architecture — `AuthenticationProvider`, `SecurityContext`, and the `SecurityContextHolder` threading strategies (THREADLOCAL, INHERITABLETHREADLOCAL, GLOBAL).
- **Late (~60%–85%)**: Moves to authorization, endpoint protection, and adapting Spring Security to new architectures; excerpts do not cover the exact chapter breakdown here.
- **Ending (~85%–100%)**: Advanced OAuth2 and OpenID Connect configuration, plus automated security testing, culminating in a customized configuration. (Excerpts do not cover these chapters in detail.)
【Key Takeaways】
- **Security is layered, and Spring Security handles the application layer** (Opening): it protects the app's environment, data, and the system it runs on — not networking or storage, which have their own practices.
- **Know the common vulnerabilities before configuring defenses** (Opening): injection attacks (SQL, LDAP, XPath, OS command) and sensitive-data exposure are recurring, high-impact mistakes that good configuration prevents.
- **Spring Security's defaults are a starting point, not a destination** (Early): a default project proves dependencies are wired correctly; real apps override user management and authorization explicitly.
- **Separate user management from authorization configuration** (Early): splitting `UserDetailsService`/`PasswordEncoder` beans from `WebSecurityConfigurerAdapter` keeps responsibilities clean and projects readable.
- **The `UserDetails` contract describes a user; `UserDetailsService` describes how to obtain one** (Early–Middle): `UserDetailsManager` extends this with create/change/delete, and implementations include in-memory, JDBC, and LDAP variants.
- **`DelegatingPasswordEncoder` lets you migrate password schemes safely** (Middle): it picks an encoder based on a hash prefix, defaulting to a chosen implementation (e.g., BCrypt) when no prefix is present.
- **Authentication is pluggable via `AuthenticationProvider`** (Middle): when username/password isn't enough (SMS codes, fingerprints, key files), you implement custom providers rather than fighting the framework.
- **`SecurityContextHolder` threading strategy matters for async code** (Middle): THREADLOCAL is the default; INHERITABLETHREADLOCAL copies context to `@Async` threads, and manually created threads need explicit context copying.
【Reading Tips】
- **Deep-read the early chapters on `UserDetails`/`UserDetailsService`/`PasswordEncoder`** — these contracts underpin everything later, and the book builds on them repeatedly.
- **Skim the vulnerability survey if you already know OWASP basics**, but don't skip it entirely; it frames why each configuration choice exists.
- **Pay close attention to the `SecurityContextHolder` threading section** — it's a common source of subtle bugs in async and reactive applications.
- **Treat the OAuth2/OpenID Connect material as the payoff** — read it after the authentication architecture clicks, not before.
- **Run the code samples**; the book is example-driven, and the cURL/Base64 walkthroughs are meant to be typed, not just read.
【Coverage Limits】
This guide is synthesized from stratified excerpts covering roughly the first half of the book; the authorization, architecture-adaptation, OAuth2/OpenID Connect, and testing chapters are referenced but not detailed in the source material.
Excerpt 1
gainst threats both common and extraordinary. What's inside • Encoding passwords and authenticating users • Securing endpoints • Automating security testing...
e app can use resources from the resource server. Figure 1.13 The OAuth 2 authorization flow with password grant type. To execute an action requested by the...
ng and maintainability. For example, the name isAccountNon- Expired() looks like a double negation, and at first sight, might create con- fusion. But analyze...
a common approach as each request has an individual thread. MODE_INHERITABLETHREADLOCAL—Similar to MODE_THREADLOCAL but also instructs Spring Security to cop...
UserDetailsService contract. For this, create a class named JpaUserDetailsService. This class uses the UserRepository we create in step 3 to obtain the detai...
ccur, one which usually creates confusion among developers. NOTE If multiple filters have the same position, the order in which they are called is not define...
mple.org The browser doesn’t allow the content from example.org because it is cross-domain. Figure 10.13 Even if the example.org page is loaded in an iframe...
client. The client uses the token to access user resources. In the second step, the user sends the OTP to prove they really are who they claim to be, and aft...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Spring Security in Action (Laurentiu Spilca)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Spring Security in Action (Laurentiu Spilca)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment