Spring Security — Java + Spring Boot Roadmap
Securing a Spring Boot application's endpoints and data
Steps in Spring Security
- Spring Security Fundamentals — advanced · The security filter chain and how requests get authenticated and authorized
- Authentication vs Authorization — advanced · The distinct roles of proving identity and granting permissions
- Form-Based & Basic Authentication — advanced · The simplest authentication mechanisms Spring Security supports out of the box
- JWT Authentication in Spring Boot — advanced · Issuing and validating stateless JSON Web Tokens for API authentication
- OAuth2 & Social Login — advanced · Delegating authentication to providers like Google or GitHub with Spring Security OAuth2
- Method-Level Security — advanced · @PreAuthorize/@PostAuthorize for fine-grained, role-based access control
- CORS & CSRF Protection — advanced · Configuring cross-origin access and understanding when CSRF protection matters for an API
Part of
- Java + Spring Boot roadmap — the full learning path