Implementasi UserDetailsService Kustom
Buat `UserDetailsService` kustom untuk memuat data khusus pengguna dari penyimpanan data aplikasi Anda saat autentikasi.
Implementasi UserDetailsService Kustom adalah pelajaran Spring Security 6 & JWT Authentication gratis di CoddyKit. Ini adalah pelajaran 1 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Spring Security 6 & JWT Authentication, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Spring Security 6 & JWT Authentication mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Beyond In-Memory Users
In previous lessons, you might have used in-memory users for simple authentication. This means usernames and passwords are hardcoded directly in your application's configuration.
While easy for testing, real-world applications need to load user data from a persistent source like a database, LDAP, or another service. This is where a custom UserDetailsService comes in!
The UserDetailsService Interface
Spring Security uses the UserDetailsService interface to retrieve user-specific data during authentication. It has just one method you need to implement:
UserDetails loadUserByUsername(String username)
This method is crucial. When a user tries to log in, Spring Security calls this method, passing the username provided by the user.
What is UserDetails?
The loadUserByUsername method must return a UserDetails object. This interface represents the authenticated user's information, including:
- Username
- Password
- Authorities (roles/permissions)
- Account status (e.g., enabled, locked, expired)
Spring Security provides a default implementation called org.springframework.security.core.userdetails.User that you'll often use.
Creating Your Custom Service
To create a custom user service, you simply create a class that implements UserDetailsService. Inside, you'll override the loadUserByUsername method.
This method is where you'll write the logic to fetch user data from your chosen data store. For now, we'll use some hardcoded examples.
Implementing loadUserByUsername
Inside loadUserByUsername, you'll perform these steps:
- Receive the
username. - Look up the user in your data source.
- If found, create a
UserDetailsobject with their details (username, password, roles). - If not found, throw a
UsernameNotFoundException.
Remember, password encoding is vital for security, but we'll cover that in a later lesson. For now, we'll use a plain text password prefix: {noop}.
Code: Basic UserDetailsService
Let's see a simple implementation. This example hardcodes users, simulating fetching from a data source. Run it to see how it works!
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.core.userdetails.UsernameNotFoundException;
import java.util.Arrays;
import java.util.Collections;
class MyUserDetailsService implements UserDetailsService {
@Override
public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
// In a real app, you'd fetch user from a database
if ("user".equals(username)) {
return User.withUsername("user")
.password("{noop}password") // {noop} for plain text
.roles("USER")
.build();
}
if ("admin".equals(username)) {
return User.withUsername("admin")
.password("{noop}adminpass")
.roles("ADMIN", "USER")
.build();
}
throw new UsernameNotFoundException("User not found: " + username);
}
}
public class Main {
public static void main(String[] args) {
MyUserDetailsService service = new MyUserDetailsService();
System.out.println("Attempting to load 'user'...");
try {
UserDetails user = service.loadUserByUsername("user");
System.out.println("Loaded User: " + user.getUsername());
System.out.println("Authorities: " + user.getAuthorities());
} catch (UsernameNotFoundException e) {
System.out.println(e.getMessage());
}
System.out.println("\nAttempting to load 'admin'...");
try {
UserDetails admin = service.loadUserByUsername("admin");
System.out.println("Loaded Admin: " + admin.getUsername());
System.out.println("Authorities: " + admin.getAuthorities());
} catch (UsernameNotFoundException e) {
System.out.println(e.getMessage());
}
System.out.println("\nAttempting to load 'unknown'...");
try {
service.loadUserByUsername("unknown");
} catch (UsernameNotFoundException e) {
System.out.println(e.getMessage());
}
}
}Adding Roles and Authorities
Notice in the example, we used .roles("USER") and .roles("ADMIN", "USER").
- Roles are high-level permissions, like 'ADMIN' or 'USER'.
- These roles are converted into GrantedAuthority objects by Spring Security.
- When building the
UserDetailsobject, you specify the roles/authorities the user possesses.
These authorities are later used by Spring Security for authorization (determining what a user can access).
Registering Your Service
Once you've created your custom UserDetailsService, Spring Security needs to know about it. In a Spring Boot application, you typically register it as a Spring bean.
By simply defining your custom service as a @Bean, Spring Security's auto-configuration will usually pick it up and use it for authentication.
The Custom Authentication Flow
Here's how custom authentication typically works with your service:
- User submits login credentials (username, password).
- Spring Security receives the request.
- It calls your custom
UserDetailsService'sloadUserByUsername()method with the provided username. - Your method fetches user data and returns a
UserDetailsobject. - Spring Security then compares the provided password with the password from
UserDetails(after encoding/decoding). - If they match, authentication succeeds!
Check Your Understanding
Consider the core purpose and components of implementing a custom UserDetailsService.
Recap: Custom UserDetailsService
You've learned how to implement a custom UserDetailsService, a fundamental component for advanced user authentication in Spring Security:
- It allows loading user data from any source.
- You implement the
loadUserByUsernamemethod. - This method returns a
UserDetailsobject, containing user credentials and authorities. - It's essential for moving beyond in-memory user management.
Next, we'll dive into securing those passwords with proper encoding!
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Implementasi UserDetailsService Kustom” gratis?
Ya — teks lengkap “Implementasi UserDetailsService Kustom” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Spring Security 6 & JWT Authentication, upgrade ke CoddyKit PRO. Kursus Spring Security 6 & JWT Authentication mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Implementasi UserDetailsService Kustom”?
Buat `UserDetailsService` kustom untuk memuat data khusus pengguna dari penyimpanan data aplikasi Anda saat autentikasi. Kamu berlatih Spring Security 6 & JWT Authentication dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Spring Security 6 & JWT Authentication?
Tidak diperlukan pengalaman sebelumnya. Spring Security 6 & JWT Authentication di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 1 dari 4.
Berapa lama pelajaran “Implementasi UserDetailsService Kustom” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Spring Security 6 & JWT Authentication ini?
Ya. Setiap pelajaran Spring Security 6 & JWT Authentication menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Implementasi UserDetailsService Kustom
- Memahami Pengode Kata Sandi
- Integrasi Pengelolaan Pengguna Basis Data
- Otorisasi Berbasis Peran dengan Granted Authorities