0Pricing
Spring Boot 4 Complete Guide · Pelajaran

Dasar-Dasar Spring Security

Siapkan Spring Security, pahami arsitekturnya, dan terapkan autentikasi dasar dalam memori.

Dasar-Dasar Spring Security adalah pelajaran Spring Boot 4 Complete Guide gratis di CoddyKit. Ini adalah pelajaran 1 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Spring Boot 4 Complete Guide, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Spring Boot 4 Complete Guide mencakup 4 pelajaran total.

Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.

Welcome to Spring Security!

Securing web applications is crucial in today's digital world. Spring Security is a powerful and highly customizable authentication and access-control framework for Spring applications.

It provides robust security features, allowing you to protect your application from common vulnerabilities and control who can access what.

Why Spring Security?

Imagine building an online store. You need to:

  • Authenticate users: Verify a user's identity (login).
  • Authorize actions: Determine what a user can do (e.g., only admins can delete products).
  • Protect against threats: CSRF, XSS, session fixation.

Spring Security handles all these complex tasks, letting you focus on your application's core logic.

Adding the Security Dependency

To get started, you just need to add the spring-boot-starter-security dependency to your project. This starter brings in all necessary Spring Security modules.

For Maven, add this to your pom.xml:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

Default Security in Action

Once the dependency is added, Spring Boot automatically configures basic security. Try running this simple application:

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@RestController
public class SecurityApp {

    public static void main(String[] args) {
        SpringApplication.run(SecurityApp.class, args);
    }

    @GetMapping("/hello")
    public String hello() {
        return "Hello, Secured World!";
    }
}

Default Login & Password

When you run the previous code with the Spring Security dependency, you'll notice something:

  • Accessing /hello redirects you to a login page.
  • Spring Security generates a random password, printed in the console at startup.

The username is typically user, and the password is the generated one. This is basic, out-of-the-box security!

AuthN vs. AuthZ

Let's clarify two fundamental concepts:

  • Authentication (AuthN): Verifying who you are. This is typically done with credentials like username/password.
  • Authorization (AuthZ): Determining what you are allowed to do once authenticated. For example, a user might be authenticated, but only an 'admin' role can delete data.

Spring Security handles both!

The Security Filter Chain

At its core, Spring Security works by intercepting HTTP requests. It uses a series of filters, called the Security Filter Chain, to apply security logic.

When a request comes in, these filters perform tasks like authentication, authorization, session management, and more, before the request even reaches your controller.

Basic In-Memory Authentication

For simple applications or testing, you can define users directly in your application's memory. This is called in-memory authentication.

You'll configure a UserDetailsService bean that provides user details. Let's see how to define a custom user with a specific role.

Configuring In-Memory Users

Here's how to define a user 'john' with password 'pass' and role 'USER'. Remember to encode passwords!

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@RestController
@EnableWebSecurity
public class SecurityConfigApp {

    public static void main(String[] args) {
        SpringApplication.run(SecurityConfigApp.class, args);
    }

    @GetMapping("/public")
    public String publicAccess() {
        return "This is a public page!";
    }

    @GetMapping("/user")
    public String userAccess() {
        return "Welcome, authenticated user!";
    }

    @Configuration
    static class WebSecurityConfig {

        @Bean
        public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
            http
                .authorizeHttpRequests(authorize -> authorize
                    .requestMatchers("/public").permitAll()
                    .requestMatchers("/user").hasRole("USER")
                    .anyRequest().authenticated()
                )
                .formLogin(login -> login
                    .permitAll()
                );
            return http.build();
        }

        @Bean
        public UserDetailsService userDetailsService(PasswordEncoder passwordEncoder) {
            UserDetails user = User.builder()
                .username("john")
                .password(passwordEncoder.encode("pass"))
                .roles("USER")
                .build();
            return new InMemoryUserDetailsManager(user);
        }

        @Bean
        public PasswordEncoder passwordEncoder() {
            return new BCryptPasswordEncoder();
        }
    }
}

Testing In-Memory Users

Run the previous application. Now try accessing:

  • http://localhost:8080/public: Should be accessible without login.
  • http://localhost:8080/user: Should redirect to login. Use username 'john' and password 'pass'.
  • http://localhost:8080/admin: Should redirect to login, then show 403 Forbidden even after logging in as 'john', because 'john' doesn't have the 'ADMIN' role.

Quick Check: Spring Security

You've learned about the basics of Spring Security and in-memory authentication. Let's test your understanding.

Lesson Summary

Great job! In this lesson, you've taken your first steps with Spring Security:

  • Understood its purpose and core concepts (AuthN, AuthZ).
  • Added the necessary dependency and observed default behavior.
  • Learned about the Security Filter Chain.
  • Implemented basic in-memory authentication with custom users and role-based URL protection.

Next, we'll explore how to handle authentication and authorization using databases and more advanced techniques!

Pertanyaan yang Sering Diajukan

Apakah pelajaran “Dasar-Dasar Spring Security” gratis?

Ya — teks lengkap “Dasar-Dasar Spring Security” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Spring Boot 4 Complete Guide, upgrade ke CoddyKit PRO. Kursus Spring Boot 4 Complete Guide mencakup 4 pelajaran total.

Apa yang akan aku pelajari di “Dasar-Dasar Spring Security”?

Siapkan Spring Security, pahami arsitekturnya, dan terapkan autentikasi dasar dalam memori. Kamu berlatih Spring Boot 4 Complete Guide dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.

Apakah aku perlu pengalaman untuk memulai Spring Boot 4 Complete Guide?

Tidak diperlukan pengalaman sebelumnya. Spring Boot 4 Complete Guide di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 1 dari 4.

Berapa lama pelajaran “Dasar-Dasar Spring Security” memakan waktu?

Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.

Bisakah aku menulis dan menjalankan kode dalam pelajaran Spring Boot 4 Complete Guide ini?

Ya. Setiap pelajaran Spring Boot 4 Complete Guide menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.

Semua pelajaran dalam kursus ini

  1. Dasar-Dasar Spring Security
  2. Autentikasi dan Otorisasi
  3. Keamanan Berbasis JWT
  4. Integrasi OAuth2 dan Login Sosial
← Kembali ke Spring Boot 4 Complete Guide