0Pricing
Spring Boot 4 Complete Guide · レッスン

JWTベースのセキュリティ

JSON Web Token(JWT)を使って、ステートレスAPIのトークンベース認証を実装します。

「JWTベースのセキュリティ」はCoddyKit上の無料Spring Boot 4 Complete Guideレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSpring Boot 4 Complete Guide学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Spring Boot 4 Complete Guideコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Intro to JWT-Based Security

Welcome to the final lesson on Spring Security! Today, we'll explore JSON Web Tokens (JWTs), a popular method for securing stateless APIs.

Unlike traditional session-based authentication, JWTs allow the server to remain stateless, making them ideal for microservices and mobile applications.

What is a JWT?

A JWT is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object.

  • Compact: Small size, can be sent through URL, POST parameter, or inside an HTTP header.
  • Self-contained: Contains all necessary information about the user, avoiding database lookups for every request.

Anatomy of a JWT

A JWT consists of three parts, separated by dots (.):

  • Header
  • Payload
  • Signature

It typically looks like: xxxxx.yyyyy.zzzzz

The Header: Algorithm & Type

The Header usually consists of two parts: the type of the token (which is JWT) and the signing algorithm being used (e.g., HS256 or RS256).

This JSON is then Base64Url-encoded to form the first part of the JWT.

{"alg":"HS256","typ":"JWT"}

The Payload: Claims

The Payload contains the 'claims' – statements about an entity (typically, the user) and additional data. There are three types of claims:

  • Registered claims: Standard, non-mandatory claims (e.g., iss for issuer, exp for expiration, sub for subject).
  • Public claims: Defined by users, require collision-resistant names.
  • Private claims: Custom claims agreed upon by sender and receiver.

The Signature: Trust & Integrity

The Signature is created by taking the encoded header, the encoded payload, a secret key, and the algorithm specified in the header. It ensures the token hasn't been tampered with.

If someone changes the header or payload, the signature verification will fail, making the token invalid. The secret key must be kept confidential!

Generating JWT Parts (Code)

Let's see how the header and payload are Base64Url-encoded. The signature would then be computed using these encoded parts and a secret.

import java.util.Base64;

public class JwtPartsDemo {
  public static void main(String[] args) {
    String headerJson = "{\"alg\":\"HS256\",\"typ\":\"JWT\"}";
    String payloadJson = "{\"sub\":\"coddyUser\",\"iat\":1678886400,\"exp\":1678890000}";
    
    String encodedHeader = Base64.getUrlEncoder().withoutPadding().encodeToString(headerJson.getBytes());
    String encodedPayload = Base64.getUrlEncoder().withoutPadding().encodeToString(payloadJson.getBytes());
    
    System.out.println("Encoded Header: " + encodedHeader);
    System.out.println("Encoded Payload: " + encodedPayload);
    System.out.println("\nJWT format: EncodedHeader.EncodedPayload.Signature");
  }
}

JWT Flow in Spring Security

When a user successfully authenticates (e.g., logs in with username/password), the server:

  1. Generates a JWT.
  2. Sends the JWT back to the client.

For subsequent requests, the client:

  1. Stores the JWT (e.g., in local storage).
  2. Attaches the JWT in the Authorization header (e.g., Bearer YOUR_TOKEN).

The server then intercepts and validates this token for each protected request.

Validating JWTs (Code Concept)

A custom filter in Spring Security would extract the token, decode its parts, and then critically, verify the signature and validate claims like expiration.

import java.util.Base64;

public class JwtValidationDemo {
  public static void main(String[] args) {
    // A simplified example token (signature part is placeholder)
    String jwtToken = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJjb2RkeVVzZXIiLCJpYXQiOjE2Nzg4ODY0MDAsImV4cCI6MTY3ODg5MDAwMH0.SIGNATURE_PLACEHOLDER";
    
    String[] parts = jwtToken.split("\\.");
    
    if (parts.length == 3) {
      String decodedHeader = new String(Base64.getUrlDecoder().decode(parts[0]));
      String decodedPayload = new String(Base64.getUrlDecoder().decode(parts[1]));
      
      System.out.println("Decoded Header: " + decodedHeader);
      System.out.println("Decoded Payload: " + decodedPayload);
      
      // In a real application, you would:
      // 1. Verify the 'SIGNATURE_PLACEHOLDER' using the secret key.
      // 2. Parse 'decodedPayload' JSON to check claims like 'exp' (expiration).
      if (decodedPayload.contains("\"sub\":\"coddyUser\"")) {
        System.out.println("Payload contains expected subject 'coddyUser'.");
      }
    } else {
      System.out.println("Invalid JWT format.");
    }
  }
}

Quick Check: JWT Parts

Based on what we've learned, which of the following are standard parts of a JSON Web Token (JWT) that are transmitted?

Recap: JWT-Based Security

In this lesson, we explored JWT-based security, understanding its three key parts: Header, Payload, and Signature.

We learned how JWTs enable stateless authentication, making them highly scalable and suitable for modern APIs and mobile applications. You also saw conceptual code examples for generating and validating JWTs.

This concludes our Spring Security course! You've learned to secure applications from basic authentication to advanced token-based systems.

よくある質問

「JWTベースのセキュリティ」レッスンは無料ですか?

はい。「JWTベースのセキュリティ」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Spring Boot 4 Complete Guideコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Spring Boot 4 Complete Guideコースには全4レッスンが含まれています。

「JWTベースのセキュリティ」で何を学びますか?

JSON Web Token(JWT)を使って、ステートレスAPIのトークンベース認証を実装します。 ブラウザで直接実行するハンズオンコードでSpring Boot 4 Complete Guideを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Spring Boot 4 Complete Guideを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのSpring Boot 4 Complete Guideは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。

「JWTベースのセキュリティ」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このSpring Boot 4 Complete Guideレッスンでコードを書いて実行できますか?

はい。すべてのSpring Boot 4 Complete Guideレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. Spring Securityの基礎
  2. 認証と認可
  3. JWTベースのセキュリティ
  4. OAuth2とソーシャルログインの統合
← Spring Boot 4 Complete Guideに戻る