Comprender la cadena de filtros de Spring Security
Examine el funcionamiento interno de Spring Security 6 para comprender cómo la cadena de filtros de servlet procesa cada solicitud y dónde encaja la autenticación.
Comprender la cadena de filtros de Spring Security es una lección gratuita de Spring Security 6 & JWT Authentication en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Spring Security 6 & JWT Authentication, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Spring Security 6 & JWT Authentication incluye 4 lecciones en total.
Partes de esta lección aún no han sido traducidas y se muestran en inglés.
How Requests Get Secured
So how does every request actually get checked? The security filter chain — a series of servlet filters Spring slots in before your controllers.
What Is a Servlet Filter?
A servlet Filter intercepts HTTP requests and responses before they reach your code. Spring Security is built almost entirely from these filters.
The DelegatingFilterProxy
The real servlet filter, DelegatingFilterProxy, hands each request to a Spring-managed bean — bridging the servlet world and the Spring context.
The FilterChainProxy
Behind that proxy sits FilterChainProxy, which holds one or more SecurityFilterChain instances and routes each request to the one that matches.
Key Filters in Order
Filters run in a fixed order: SecurityContextHolderFilter loads context, the auth filter handles login, and AuthorizationFilter enforces access rules.
Defining a SecurityFilterChain Bean
In Spring Security 6 you configure everything by declaring a SecurityFilterChain bean — the modern replacement for WebSecurityConfigurerAdapter. See below.
@Bean
SecurityFilterChain chain(HttpSecurity http) throws Exception {
http.authorizeHttpRequests(a -> a.anyRequest().authenticated())
.formLogin(Customizer.withDefaults());
return http.build();
}Where the SecurityContext Lives
After login, the Authentication is stored in the SecurityContext and stays reachable via SecurityContextHolder for the rest of the request.
Authentication auth = SecurityContextHolder.getContext().getAuthentication();Permitting Some Paths
Let public paths through while securing the rest — all on the same chain. The code uses permitAll() for /public and authenticated() for everything else.
http.authorizeHttpRequests(a -> a
.requestMatchers('/public/**').permitAll()
.anyRequest().authenticated());Multiple Filter Chains
Register several SecurityFilterChain beans with securityMatcher so API and web paths get different rules. The first matching chain wins.
http.securityMatcher('/api/**');Adding a Custom Filter
Slot your own filter at a precise position with addFilterBefore — the foundation for the JWT processing you'll build later in this course.
http.addFilterBefore(myFilter, UsernamePasswordAuthenticationFilter.class);Why This Matters
Knowing the chain explains why ordering matters, where auth versus authz happens, and exactly where a custom JWT filter has to plug in.
Quick Check
In Spring Security 6, how do you define your security configuration?
Recap
Recap: requests flow DelegatingFilterProxy to FilterChainProxy to SecurityFilterChain; filters run in order, auth then authz, and addFilterBefore inserts custom ones.
Preguntas frecuentes
¿La lección «Comprender la cadena de filtros de Spring Security» es gratis?
Sí — el texto completo de «Comprender la cadena de filtros de Spring Security» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Spring Security 6 & JWT Authentication, actualiza a CoddyKit PRO. El curso de Spring Security 6 & JWT Authentication incluye 4 lecciones en total.
¿Qué aprenderé en «Comprender la cadena de filtros de Spring Security»?
Examine el funcionamiento interno de Spring Security 6 para comprender cómo la cadena de filtros de servlet procesa cada solicitud y dónde encaja la autenticación. Practicas Spring Security 6 & JWT Authentication con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.
¿Necesito experiencia previa para empezar Spring Security 6 & JWT Authentication?
No se requiere experiencia previa. Spring Security 6 & JWT Authentication en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.
¿Cuánto tiempo toma la lección «Comprender la cadena de filtros de Spring Security»?
La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.
¿Puedo escribir y ejecutar código en esta lección de Spring Security 6 & JWT Authentication?
Sí. Cada lección de Spring Security 6 & JWT Authentication incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.
Todas las lecciones de este curso
- Introducción a Spring Security 6
- Configuración del proyecto y dependencias
- Autenticación de usuarios en memoria
- Comprender la cadena de filtros de Spring Security