Sécurité fondée sur les JWT
Mettez en œuvre une authentification fondée sur des jetons à l’aide de jetons Web JSON (JWT) pour des API sans état.
Sécurité fondée sur les JWT est une leçon Spring Boot 4 Complete Guide gratuite sur CoddyKit. Ceci est la leçon 3 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Spring Boot 4 Complete Guide, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Spring Boot 4 Complete Guide comprend 4 leçons au total.
Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.
Intro to JWT-Based Security
Welcome to the final lesson on Spring Security! Today, we'll explore JSON Web Tokens (JWTs), a popular method for securing stateless APIs.
Unlike traditional session-based authentication, JWTs allow the server to remain stateless, making them ideal for microservices and mobile applications.
What is a JWT?
A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object.
- Compact: Small size, can be sent through URL, POST parameter, or inside an HTTP header.
- Self-contained: Contains all necessary information about the user, avoiding database lookups for every request.
Anatomy of a JWT
A JWT consists of three parts, separated by dots (.):
- Header
- Payload
- Signature
It typically looks like: xxxxx.yyyyy.zzzzz
The Header: Algorithm & Type
The Header usually consists of two parts: the type of the token (which is JWT) and the signing algorithm being used (e.g., HS256 or RS256).
This JSON is then Base64Url-encoded to form the first part of the JWT.
{"alg":"HS256","typ":"JWT"}The Payload: Claims
The Payload contains the 'claims' – statements about an entity (typically, the user) and additional data. There are three types of claims:
- Registered claims: Standard, non-mandatory claims (e.g.,
issfor issuer,expfor expiration,subfor subject). - Public claims: Defined by users, require collision-resistant names.
- Private claims: Custom claims agreed upon by sender and receiver.
The Signature: Trust & Integrity
The Signature is created by taking the encoded header, the encoded payload, a secret key, and the algorithm specified in the header. It ensures the token hasn't been tampered with.
If someone changes the header or payload, the signature verification will fail, making the token invalid. The secret key must be kept confidential!
Generating JWT Parts (Code)
Let's see how the header and payload are Base64Url-encoded. The signature would then be computed using these encoded parts and a secret.
import java.util.Base64;
public class JwtPartsDemo {
public static void main(String[] args) {
String headerJson = "{\"alg\":\"HS256\",\"typ\":\"JWT\"}";
String payloadJson = "{\"sub\":\"coddyUser\",\"iat\":1678886400,\"exp\":1678890000}";
String encodedHeader = Base64.getUrlEncoder().withoutPadding().encodeToString(headerJson.getBytes());
String encodedPayload = Base64.getUrlEncoder().withoutPadding().encodeToString(payloadJson.getBytes());
System.out.println("Encoded Header: " + encodedHeader);
System.out.println("Encoded Payload: " + encodedPayload);
System.out.println("\nJWT format: EncodedHeader.EncodedPayload.Signature");
}
}JWT Flow in Spring Security
When a user successfully authenticates (e.g., logs in with username/password), the server:
- Generates a JWT.
- Sends the JWT back to the client.
For subsequent requests, the client:
- Stores the JWT (e.g., in local storage).
- Attaches the JWT in the
Authorizationheader (e.g.,Bearer YOUR_TOKEN).
The server then intercepts and validates this token for each protected request.
Validating JWTs (Code Concept)
A custom filter in Spring Security would extract the token, decode its parts, and then critically, verify the signature and validate claims like expiration.
import java.util.Base64;
public class JwtValidationDemo {
public static void main(String[] args) {
// A simplified example token (signature part is placeholder)
String jwtToken = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJjb2RkeVVzZXIiLCJpYXQiOjE2Nzg4ODY0MDAsImV4cCI6MTY3ODg5MDAwMH0.SIGNATURE_PLACEHOLDER";
String[] parts = jwtToken.split("\\.");
if (parts.length == 3) {
String decodedHeader = new String(Base64.getUrlDecoder().decode(parts[0]));
String decodedPayload = new String(Base64.getUrlDecoder().decode(parts[1]));
System.out.println("Decoded Header: " + decodedHeader);
System.out.println("Decoded Payload: " + decodedPayload);
// In a real application, you would:
// 1. Verify the 'SIGNATURE_PLACEHOLDER' using the secret key.
// 2. Parse 'decodedPayload' JSON to check claims like 'exp' (expiration).
if (decodedPayload.contains("\"sub\":\"coddyUser\"")) {
System.out.println("Payload contains expected subject 'coddyUser'.");
}
} else {
System.out.println("Invalid JWT format.");
}
}
}Quick Check: JWT Parts
Based on what we've learned, which of the following are standard parts of a JSON Web Token (JWT) that are transmitted?
Recap: JWT-Based Security
In this lesson, we explored JWT-based security, understanding its three key parts: Header, Payload, and Signature.
We learned how JWTs enable stateless authentication, making them highly scalable and suitable for modern APIs and mobile applications. You also saw conceptual code examples for generating and validating JWTs.
This concludes our Spring Security course! You've learned to secure applications from basic authentication to advanced token-based systems.
Questions Fréquemment Posées
La leçon « Sécurité fondée sur les JWT » est-elle gratuite ?
Oui — le texte complet de « Sécurité fondée sur les JWT » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Spring Boot 4 Complete Guide, passe à CoddyKit PRO. Le cours Spring Boot 4 Complete Guide comprend 4 leçons au total.
Qu'est-ce que j'apprendrai dans « Sécurité fondée sur les JWT » ?
Mettez en œuvre une authentification fondée sur des jetons à l’aide de jetons Web JSON (JWT) pour des API sans état. Tu pratiques Spring Boot 4 Complete Guide avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.
Dois-je avoir de l'expérience pour commencer Spring Boot 4 Complete Guide ?
Aucune expérience préalable n'est requise. Spring Boot 4 Complete Guide sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 3 sur 4.
Combien de temps prend la leçon « Sécurité fondée sur les JWT » ?
La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.
Peux-tu écrire et exécuter du code dans cette leçon Spring Boot 4 Complete Guide ?
Oui. Chaque leçon Spring Boot 4 Complete Guide inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.
Toutes les leçons de ce cours
- Fondamentaux de Spring Security
- Authentification et autorisation
- Sécurité fondée sur les JWT
- Intégration d’OAuth2 et de la connexion sociale