Spring Security 6 & JWT Authentication · Lezione

Applicazione di scope e claim

Applichi scope e claim specifici ai JWT ricevuti per controllare l'accesso alle diverse parti della sua API.

Lezione 3 di 411 passaggi

Applicazione di scope e claim è una lezione Spring Security 6 & JWT Authentication gratuita su CoddyKit. Questa è la lezione 3 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Spring Security 6 & JWT Authentication, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Spring Security 6 & JWT Authentication include 4 lezioni in totale.

Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.

Authorization with Scopes & Claims

Welcome! In this lesson, we'll learn how to control access to your API endpoints using scopes and claims in an OAuth2 Resource Server.

These are crucial components of a JSON Web Token (JWT) that tell your server who the user is and what they are allowed to do.

Understanding OAuth2 Scopes

Think of scopes as specific permissions or access rights that a client application requests on behalf of a user.

  • They are defined by the Resource Server.
  • Examples: read, write, profile, email.
  • When a user grants permission, these scopes are included in the issued JWT.

They define the "what" a client can do within the API.

JWT Claims Explained

Claims are pieces of information about the user or the token itself, stored as key-value pairs inside the JWT payload.

  • Standard Claims: sub (subject/user ID), exp (expiration time), iss (issuer).
  • Custom Claims: You can add your own data, like role, department, or user_id.

Claims provide context about "who" the user is and their specific attributes.

Spring Security & Scopes Mapping

When Spring Security processes an incoming JWT, it automatically extracts the scopes from the token.

It then converts these scopes into Spring Security authorities by prefixing them with SCOPE_.

For example, a scope read becomes an authority SCOPE_read, which can then be checked using expression language.

@PreAuthorize for Scopes

You can enforce scope-based authorization on your API methods using Spring Security's @PreAuthorize annotation.

This annotation allows you to define SpEL (Spring Expression Language) expressions that must evaluate to true for the method to be executed.

Use hasAuthority('SCOPE_<your_scope>') to check for a specific scope.

Scope Protection Demo

Let's see how to protect an endpoint using the SCOPE_read authority. Only tokens with the 'read' scope can access this resource.

package com.coddykit.security;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.security.access.prepost.PreAuthorize;

@SpringBootApplication
@EnableMethodSecurity // Enable @PreAuthorize
public class Main {
  public static void main(String[] args) {
    SpringApplication.run(Main.class, args);
  }
}

@Configuration
class SecurityConfig {
  @Bean
  SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
      .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
      .oauth2ResourceServer(oauth2 -> oauth2.jwt(jwt -> {}))
      .csrf(csrf -> csrf.disable()); // For simplicity in demo
    return http.build();
  }
}

@RestController
class DataController {
  @GetMapping("/data/public")
  public String getPublicData() {
    return "This is public data (authenticated)";
  }

  @GetMapping("/data/secret")
  @PreAuthorize("hasAuthority('SCOPE_read')")
  public String getSecretData() {
    return "This is secret data, requires 'read' scope!";
  }
}

Leveraging Custom Claims

While scopes are great for general permissions, custom claims allow for more fine-grained or context-specific authorization.

For example, you might have a role claim with values like ADMIN or USER, or a department_id claim.

These claims are directly accessible from the authenticated principal in Spring Security, offering rich contextual data.

@PreAuthorize for Claims

You can also use @PreAuthorize to check for specific claims in the JWT payload.

Spring Security's SpEL allows you to access the authenticated principal's claims directly.

Use expressions like #oauth2.token.claims['role'] == 'ADMIN' or #oauth2.token.claims['department'] == 'IT'.

Claim Protection Demo

Here's an example of an endpoint protected by a custom role claim. Only users with role:ADMIN can access this sensitive data.

package com.coddykit.security;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.security.access.prepost.PreAuthorize;

@SpringBootApplication
@EnableMethodSecurity
public class Main {
  public static void main(String[] args) {
    SpringApplication.run(Main.class, args);
  }
}

@Configuration
class SecurityConfig {
  @Bean
  SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
      .authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
      .oauth2ResourceServer(oauth2 -> oauth2.jwt(jwt -> {}))
      .csrf(csrf -> csrf.disable());
    return http.build();
  }
}

@RestController
class AdminController {
  @GetMapping("/admin/report")
  @PreAuthorize("#oauth2.token.claims['role'] == 'ADMIN'")
  public String getAdminReport() {
    return "Sensitive admin report data!";
  }

  @GetMapping("/admin/dashboard")
  @PreAuthorize("hasAuthority('SCOPE_admin') and #oauth2.token.claims['department'] == 'IT'")
  public String getITAdminDashboard() {
    return "IT Department Admin Dashboard!";
  }
}

Quick Check: Scopes & Claims

Which of the following statements correctly describe the use of scopes and claims in Spring Security for an OAuth2 Resource Server?

Recap: Scopes & Claims

We've covered how scopes and claims are fundamental for authorization in an OAuth2 Resource Server.

  • Scopes define broad permissions (e.g., read, write).
  • Claims provide detailed user attributes (e.g., role, department).
  • Both can be enforced using @PreAuthorize with SpEL expressions.

Mastering these allows for robust and flexible access control in your APIs!

Gratis per iniziare

Impara Java con un tutor IA — gratis

Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.

Corsi
12
Lezioni
48

Domande Frequenti

La lezione «Applicazione di scope e claim» è gratuita?

Sì — il testo completo di «Applicazione di scope e claim» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Spring Security 6 & JWT Authentication, passa a CoddyKit PRO. Il corso Spring Security 6 & JWT Authentication include 4 lezioni in totale.

Cosa imparerò in «Applicazione di scope e claim»?

Applichi scope e claim specifici ai JWT ricevuti per controllare l'accesso alle diverse parti della sua API. Eserciti Spring Security 6 & JWT Authentication con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.

Ho bisogno di esperienza per iniziare Spring Security 6 & JWT Authentication?

Non è richiesta alcuna esperienza precedente. Spring Security 6 & JWT Authentication su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 3 di 4.

Quanto tempo richiede la lezione «Applicazione di scope e claim»?

La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.

Posso scrivere ed eseguire codice in questa lezione Spring Security 6 & JWT Authentication?

Sì. Ogni lezione Spring Security 6 & JWT Authentication include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.

Tutte le lezioni di questo corso

  1. Configurazione del Resource Server
  2. Decodifica e convalida dei JWT
  3. Applicazione di scope e claim
  4. Mappare i claim JWT sulle autorità di Spring
← Torna a Spring Security 6 & JWT Authentication