Fondamentaux de Spring Security
Configurez Spring Security, comprenez son architecture et mettez en œuvre une authentification de base en mémoire.
Fondamentaux de Spring Security est une leçon Spring Boot 4 Complete Guide gratuite sur CoddyKit. Ceci est la leçon 1 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Spring Boot 4 Complete Guide, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Spring Boot 4 Complete Guide comprend 4 leçons au total.
Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.
Welcome to Spring Security!
Securing web applications is crucial in today's digital world. Spring Security is a powerful and highly customizable authentication and access-control framework for Spring applications.
It provides robust security features, allowing you to protect your application from common vulnerabilities and control who can access what.
Why Spring Security?
Imagine building an online store. You need to:
- Authenticate users: Verify a user's identity (login).
- Authorize actions: Determine what a user can do (e.g., only admins can delete products).
- Protect against threats: CSRF, XSS, session fixation.
Spring Security handles all these complex tasks, letting you focus on your application's core logic.
Adding the Security Dependency
To get started, you just need to add the spring-boot-starter-security dependency to your project. This starter brings in all necessary Spring Security modules.
For Maven, add this to your pom.xml:
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>Default Security in Action
Once the dependency is added, Spring Boot automatically configures basic security. Try running this simple application:
package com.coddykit;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@SpringBootApplication
@RestController
public class SecurityApp {
public static void main(String[] args) {
SpringApplication.run(SecurityApp.class, args);
}
@GetMapping("/hello")
public String hello() {
return "Hello, Secured World!";
}
}Default Login & Password
When you run the previous code with the Spring Security dependency, you'll notice something:
- Accessing
/helloredirects you to a login page. - Spring Security generates a random password, printed in the console at startup.
The username is typically user, and the password is the generated one. This is basic, out-of-the-box security!
AuthN vs. AuthZ
Let's clarify two fundamental concepts:
- Authentication (AuthN): Verifying who you are. This is typically done with credentials like username/password.
- Authorization (AuthZ): Determining what you are allowed to do once authenticated. For example, a user might be authenticated, but only an 'admin' role can delete data.
Spring Security handles both!
The Security Filter Chain
At its core, Spring Security works by intercepting HTTP requests. It uses a series of filters, called the Security Filter Chain, to apply security logic.
When a request comes in, these filters perform tasks like authentication, authorization, session management, and more, before the request even reaches your controller.
Basic In-Memory Authentication
For simple applications or testing, you can define users directly in your application's memory. This is called in-memory authentication.
You'll configure a UserDetailsService bean that provides user details. Let's see how to define a custom user with a specific role.
Configuring In-Memory Users
Here's how to define a user 'john' with password 'pass' and role 'USER'. Remember to encode passwords!
package com.coddykit;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@SpringBootApplication
@RestController
@EnableWebSecurity
public class SecurityConfigApp {
public static void main(String[] args) {
SpringApplication.run(SecurityConfigApp.class, args);
}
@GetMapping("/public")
public String publicAccess() {
return "This is a public page!";
}
@GetMapping("/user")
public String userAccess() {
return "Welcome, authenticated user!";
}
@Configuration
static class WebSecurityConfig {
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(authorize -> authorize
.requestMatchers("/public").permitAll()
.requestMatchers("/user").hasRole("USER")
.anyRequest().authenticated()
)
.formLogin(login -> login
.permitAll()
);
return http.build();
}
@Bean
public UserDetailsService userDetailsService(PasswordEncoder passwordEncoder) {
UserDetails user = User.builder()
.username("john")
.password(passwordEncoder.encode("pass"))
.roles("USER")
.build();
return new InMemoryUserDetailsManager(user);
}
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
}
}Testing In-Memory Users
Run the previous application. Now try accessing:
http://localhost:8080/public: Should be accessible without login.http://localhost:8080/user: Should redirect to login. Use username 'john' and password 'pass'.http://localhost:8080/admin: Should redirect to login, then show 403 Forbidden even after logging in as 'john', because 'john' doesn't have the 'ADMIN' role.
Quick Check: Spring Security
You've learned about the basics of Spring Security and in-memory authentication. Let's test your understanding.
Lesson Summary
Great job! In this lesson, you've taken your first steps with Spring Security:
- Understood its purpose and core concepts (AuthN, AuthZ).
- Added the necessary dependency and observed default behavior.
- Learned about the Security Filter Chain.
- Implemented basic in-memory authentication with custom users and role-based URL protection.
Next, we'll explore how to handle authentication and authorization using databases and more advanced techniques!
Apprends Java avec un tuteur IA — gratuit
Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.
- Cours
- 21
- Leçons
- 84
Questions Fréquemment Posées
La leçon « Fondamentaux de Spring Security » est-elle gratuite ?
Oui — le texte complet de « Fondamentaux de Spring Security » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Spring Boot 4 Complete Guide, passe à CoddyKit PRO. Le cours Spring Boot 4 Complete Guide comprend 4 leçons au total.
Qu'est-ce que j'apprendrai dans « Fondamentaux de Spring Security » ?
Configurez Spring Security, comprenez son architecture et mettez en œuvre une authentification de base en mémoire. Tu pratiques Spring Boot 4 Complete Guide avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.
Dois-je avoir de l'expérience pour commencer Spring Boot 4 Complete Guide ?
Aucune expérience préalable n'est requise. Spring Boot 4 Complete Guide sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 1 sur 4.
Combien de temps prend la leçon « Fondamentaux de Spring Security » ?
La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.
Peux-tu écrire et exécuter du code dans cette leçon Spring Boot 4 Complete Guide ?
Oui. Chaque leçon Spring Boot 4 Complete Guide inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.
Toutes les leçons de ce cours
- Fondamentaux de Spring Security
- Authentification et autorisation
- Sécurité fondée sur les JWT
- Intégration d’OAuth2 et de la connexion sociale