Implementazione personalizzata di UserDetailsService
Crei un `UserDetailsService` personalizzato per caricare i dati specifici degli utenti dall’archivio dati dell’applicazione durante l’autenticazione.
Implementazione personalizzata di UserDetailsService è una lezione Spring Security 6 & JWT Authentication gratuita su CoddyKit. Questa è la lezione 1 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Spring Security 6 & JWT Authentication, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Spring Security 6 & JWT Authentication include 4 lezioni in totale.
Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.
Beyond In-Memory Users
In previous lessons, you might have used in-memory users for simple authentication. This means usernames and passwords are hardcoded directly in your application's configuration.
While easy for testing, real-world applications need to load user data from a persistent source like a database, LDAP, or another service. This is where a custom UserDetailsService comes in!
The UserDetailsService Interface
Spring Security uses the UserDetailsService interface to retrieve user-specific data during authentication. It has just one method you need to implement:
UserDetails loadUserByUsername(String username)
This method is crucial. When a user tries to log in, Spring Security calls this method, passing the username provided by the user.
What is UserDetails?
The loadUserByUsername method must return a UserDetails object. This interface represents the authenticated user's information, including:
- Username
- Password
- Authorities (roles/permissions)
- Account status (e.g., enabled, locked, expired)
Spring Security provides a default implementation called org.springframework.security.core.userdetails.User that you'll often use.
Creating Your Custom Service
To create a custom user service, you simply create a class that implements UserDetailsService. Inside, you'll override the loadUserByUsername method.
This method is where you'll write the logic to fetch user data from your chosen data store. For now, we'll use some hardcoded examples.
Implementing loadUserByUsername
Inside loadUserByUsername, you'll perform these steps:
- Receive the
username. - Look up the user in your data source.
- If found, create a
UserDetailsobject with their details (username, password, roles). - If not found, throw a
UsernameNotFoundException.
Remember, password encoding is vital for security, but we'll cover that in a later lesson. For now, we'll use a plain text password prefix: {noop}.
Code: Basic UserDetailsService
Let's see a simple implementation. This example hardcodes users, simulating fetching from a data source. Run it to see how it works!
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.core.userdetails.UsernameNotFoundException;
import java.util.Arrays;
import java.util.Collections;
class MyUserDetailsService implements UserDetailsService {
@Override
public UserDetails loadUserByUsername(String username) throws UsernameNotFoundException {
// In a real app, you'd fetch user from a database
if ("user".equals(username)) {
return User.withUsername("user")
.password("{noop}password") // {noop} for plain text
.roles("USER")
.build();
}
if ("admin".equals(username)) {
return User.withUsername("admin")
.password("{noop}adminpass")
.roles("ADMIN", "USER")
.build();
}
throw new UsernameNotFoundException("User not found: " + username);
}
}
public class Main {
public static void main(String[] args) {
MyUserDetailsService service = new MyUserDetailsService();
System.out.println("Attempting to load 'user'...");
try {
UserDetails user = service.loadUserByUsername("user");
System.out.println("Loaded User: " + user.getUsername());
System.out.println("Authorities: " + user.getAuthorities());
} catch (UsernameNotFoundException e) {
System.out.println(e.getMessage());
}
System.out.println("\nAttempting to load 'admin'...");
try {
UserDetails admin = service.loadUserByUsername("admin");
System.out.println("Loaded Admin: " + admin.getUsername());
System.out.println("Authorities: " + admin.getAuthorities());
} catch (UsernameNotFoundException e) {
System.out.println(e.getMessage());
}
System.out.println("\nAttempting to load 'unknown'...");
try {
service.loadUserByUsername("unknown");
} catch (UsernameNotFoundException e) {
System.out.println(e.getMessage());
}
}
}Adding Roles and Authorities
Notice in the example, we used .roles("USER") and .roles("ADMIN", "USER").
- Roles are high-level permissions, like 'ADMIN' or 'USER'.
- These roles are converted into GrantedAuthority objects by Spring Security.
- When building the
UserDetailsobject, you specify the roles/authorities the user possesses.
These authorities are later used by Spring Security for authorization (determining what a user can access).
Registering Your Service
Once you've created your custom UserDetailsService, Spring Security needs to know about it. In a Spring Boot application, you typically register it as a Spring bean.
By simply defining your custom service as a @Bean, Spring Security's auto-configuration will usually pick it up and use it for authentication.
The Custom Authentication Flow
Here's how custom authentication typically works with your service:
- User submits login credentials (username, password).
- Spring Security receives the request.
- It calls your custom
UserDetailsService'sloadUserByUsername()method with the provided username. - Your method fetches user data and returns a
UserDetailsobject. - Spring Security then compares the provided password with the password from
UserDetails(after encoding/decoding). - If they match, authentication succeeds!
Check Your Understanding
Consider the core purpose and components of implementing a custom UserDetailsService.
Recap: Custom UserDetailsService
You've learned how to implement a custom UserDetailsService, a fundamental component for advanced user authentication in Spring Security:
- It allows loading user data from any source.
- You implement the
loadUserByUsernamemethod. - This method returns a
UserDetailsobject, containing user credentials and authorities. - It's essential for moving beyond in-memory user management.
Next, we'll dive into securing those passwords with proper encoding!
Domande Frequenti
La lezione «Implementazione personalizzata di UserDetailsService» è gratuita?
Sì — il testo completo di «Implementazione personalizzata di UserDetailsService» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Spring Security 6 & JWT Authentication, passa a CoddyKit PRO. Il corso Spring Security 6 & JWT Authentication include 4 lezioni in totale.
Cosa imparerò in «Implementazione personalizzata di UserDetailsService»?
Crei un `UserDetailsService` personalizzato per caricare i dati specifici degli utenti dall’archivio dati dell’applicazione durante l’autenticazione. Eserciti Spring Security 6 & JWT Authentication con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.
Ho bisogno di esperienza per iniziare Spring Security 6 & JWT Authentication?
Non è richiesta alcuna esperienza precedente. Spring Security 6 & JWT Authentication su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 1 di 4.
Quanto tempo richiede la lezione «Implementazione personalizzata di UserDetailsService»?
La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.
Posso scrivere ed eseguire codice in questa lezione Spring Security 6 & JWT Authentication?
Sì. Ogni lezione Spring Security 6 & JWT Authentication include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.
Tutte le lezioni di questo corso
- Implementazione personalizzata di UserDetailsService
- Comprendere i password encoder
- Integrazione della gestione degli utenti nel database
- Autorizzazione basata sui ruoli con le Granted Authorities