0Pricing
API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) · Leçon

Authentification et autorisation avec JWT

Mettez en œuvre une authentification et une autorisation fondées sur JWT dans Spring Cloud Gateway afin de sécuriser l’accès aux API.

Authentification et autorisation avec JWT est une leçon API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) gratuite sur CoddyKit. Ceci est la leçon 1 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), et ta progression se synchronise sur le web et l'application CoddyKit. Le cours API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Securing Your API Gateway

In a microservices architecture, securing your APIs is paramount. Spring Cloud Gateway acts as a central entry point, making it the perfect place to enforce security policies.

This lesson focuses on using JSON Web Tokens (JWTs) for both authentication (who is this user?) and authorization (what can this user do?) directly within your Gateway.

Introducing JSON Web Tokens (JWTs)

A JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. It's often used for authentication and information exchange.

  • Stateless: The server doesn't need to store session information.
  • Self-contained: Contains all the necessary user information and claims.
  • Scalable: Easy to use across multiple services without complex session management.

JWT Structure: Header, Payload, Signature

A JWT consists of three parts, separated by dots (.), which are Base64Url-encoded:

  • Header: Specifies the token type (JWT) and the signing algorithm (e.g., HMAC SHA256).
  • Payload: Contains the claims (statements about an entity, like a user ID or roles).
  • Signature: Used to verify the token's authenticity and ensure it hasn't been tampered with. It's created using the header, payload, and a secret key.

AuthN vs. AuthZ in the Gateway

It's crucial to distinguish between Authentication (AuthN) and Authorization (AuthZ):

  • Authentication: Verifying the identity of a user or service (e.g., validating a JWT's signature and expiration).
  • Authorization: Determining if an authenticated user or service has permission to perform a specific action or access a particular resource (e.g., checking user roles from JWT claims).

The Gateway can handle both, ensuring only valid and authorized requests reach your backend services.

Setting Up Gateway for JWT Security

To integrate JWT security, your Spring Cloud Gateway project typically needs the spring-cloud-starter-gateway and spring-boot-starter-security dependencies.

While spring-boot-starter-security provides a robust security framework, we'll focus on manually handling JWT validation using Gateway filters to illustrate the core concepts.

JWT Validation Flow in Gateway

When a client sends a request with a JWT, the Gateway intercepts it. The typical flow is:

  1. Extract Token: Get the JWT from the Authorization header.
  2. Validate Token: Verify its signature, check expiration, and ensure it's well-formed.
  3. Extract Claims: Parse the token to get user details and roles.
  4. Authorize Request: Based on claims, decide if the request can proceed to the backend service.

Implementing a Custom JWT Filter

We can implement JWT validation using a custom GlobalFilter in Spring Cloud Gateway. This filter will run for all incoming requests before they are routed.

Inside the filter, you'll access the request headers, extract the JWT, and perform your validation logic. If the token is invalid, you can reject the request directly from the Gateway.

Example: Simple JWT Filter

This example demonstrates a basic Spring Cloud Gateway application with a GlobalFilter. It logs the presence of an Authorization: Bearer header, simulating the first step of JWT validation. Run it and try accessing /test with an Authorization header!

package com.example.gateway;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.cloud.gateway.route.RouteLocator;
import org.springframework.cloud.gateway.route.builder.RouteLocatorBuilder;
import org.springframework.context.annotation.Bean;
import org.springframework.cloud.gateway.filter.GlobalFilter;
import org.springframework.http.HttpHeaders;
import reactor.core.publisher.Mono;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

@SpringBootApplication
public class GatewayApplication {

    public static void main(String[] args) {
        SpringApplication.run(GatewayApplication.class, args);
        System.out.println("Gateway started! Try accessing /test with 'Authorization' header.");
    }

    // Configures a dummy route for the filter to act on
    @Bean
    public RouteLocator customRouteLocator(RouteLocatorBuilder builder) {
        return builder.routes()
            .route("test_route", r -> r.path("/test")
                .uri("http://httpbin.org:80/get")) // A public echo service
            .build();
    }

    // Our simplified JWT validation filter
    @Bean
    public GlobalFilter jwtValidationFilter() {
        Logger logger = LoggerFactory.getLogger(GatewayApplication.class);
        return (exchange, chain) -> {
            HttpHeaders headers = exchange.getRequest().getHeaders();
            String authHeader = headers.getFirst(HttpHeaders.AUTHORIZATION);

            logger.info("Intercepted request to: {}", exchange.getRequest().getURI());

            if (authHeader != null && authHeader.startsWith("Bearer ")) {
                String jwt = authHeader.substring(7);
                logger.info("Found JWT in header: {}", jwt);
                // In a real scenario, full JWT validation happens here.
                // For this example, we just log it and proceed.
            } else {
                logger.warn("No 'Authorization: Bearer' header found.");
            }
            return chain.filter(exchange); // Continue to the next filter/route
        };
    }
}

Securing Routes with Authorization

Once a JWT is validated and its claims (like user roles or scopes) are extracted, you can use these claims for authorization. Spring Cloud Gateway allows you to define authorization rules directly on your routes.

For instance, you could configure a route to only permit requests if the authenticated user has an 'ADMIN' role specified in their JWT payload.

Quick Check: JWT Authorization

After a JWT is validated by the Gateway, which of the following are key benefits of using JWTs for API authentication and authorization in a stateless microservice architecture?

Recap: Secure Gateway with JWTs

You've learned how Spring Cloud Gateway serves as a critical enforcement point for API security. We covered the basics of JWTs—their structure, benefits, and how they enable stateless authentication and authorization.

By implementing custom filters, you can integrate robust JWT validation and leverage claims to secure access to your microservices, ensuring only authorized requests reach your backend.

Questions Fréquemment Posées

La leçon « Authentification et autorisation avec JWT » est-elle gratuite ?

Oui — le texte complet de « Authentification et autorisation avec JWT » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), passe à CoddyKit PRO. Le cours API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Authentification et autorisation avec JWT » ?

Mettez en œuvre une authentification et une autorisation fondées sur JWT dans Spring Cloud Gateway afin de sécuriser l’accès aux API. Tu pratiques API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) ?

Aucune expérience préalable n'est requise. API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 1 sur 4.

Combien de temps prend la leçon « Authentification et autorisation avec JWT » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) ?

Oui. Chaque leçon API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Authentification et autorisation avec JWT
  2. Traçage distribué avec Sleuth et Zipkin
  3. Configuration centralisée avec Config Server
  4. Exposer les métriques avec Actuator et Prometheus
← Retour à API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)