Spring Securityの基礎
Spring Securityを設定し、そのアーキテクチャを理解して、基本的なインメモリ認証を実装します。
「Spring Securityの基礎」はCoddyKit上の無料Spring Boot 4 Complete Guideレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSpring Boot 4 Complete Guide学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Spring Boot 4 Complete Guideコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Welcome to Spring Security!
Securing web applications is crucial in today's digital world. Spring Security is a powerful and highly customizable authentication and access-control framework for Spring applications.
It provides robust security features, allowing you to protect your application from common vulnerabilities and control who can access what.
Why Spring Security?
Imagine building an online store. You need to:
- Authenticate users: Verify a user's identity (login).
- Authorize actions: Determine what a user can do (e.g., only admins can delete products).
- Protect against threats: CSRF, XSS, session fixation.
Spring Security handles all these complex tasks, letting you focus on your application's core logic.
Adding the Security Dependency
To get started, you just need to add the spring-boot-starter-security dependency to your project. This starter brings in all necessary Spring Security modules.
For Maven, add this to your pom.xml:
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>Default Security in Action
Once the dependency is added, Spring Boot automatically configures basic security. Try running this simple application:
package com.coddykit;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@SpringBootApplication
@RestController
public class SecurityApp {
public static void main(String[] args) {
SpringApplication.run(SecurityApp.class, args);
}
@GetMapping("/hello")
public String hello() {
return "Hello, Secured World!";
}
}Default Login & Password
When you run the previous code with the Spring Security dependency, you'll notice something:
- Accessing
/helloredirects you to a login page. - Spring Security generates a random password, printed in the console at startup.
The username is typically user, and the password is the generated one. This is basic, out-of-the-box security!
AuthN vs. AuthZ
Let's clarify two fundamental concepts:
- Authentication (AuthN): Verifying who you are. This is typically done with credentials like username/password.
- Authorization (AuthZ): Determining what you are allowed to do once authenticated. For example, a user might be authenticated, but only an 'admin' role can delete data.
Spring Security handles both!
The Security Filter Chain
At its core, Spring Security works by intercepting HTTP requests. It uses a series of filters, called the Security Filter Chain, to apply security logic.
When a request comes in, these filters perform tasks like authentication, authorization, session management, and more, before the request even reaches your controller.
Basic In-Memory Authentication
For simple applications or testing, you can define users directly in your application's memory. This is called in-memory authentication.
You'll configure a UserDetailsService bean that provides user details. Let's see how to define a custom user with a specific role.
Configuring In-Memory Users
Here's how to define a user 'john' with password 'pass' and role 'USER'. Remember to encode passwords!
package com.coddykit;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@SpringBootApplication
@RestController
@EnableWebSecurity
public class SecurityConfigApp {
public static void main(String[] args) {
SpringApplication.run(SecurityConfigApp.class, args);
}
@GetMapping("/public")
public String publicAccess() {
return "This is a public page!";
}
@GetMapping("/user")
public String userAccess() {
return "Welcome, authenticated user!";
}
@Configuration
static class WebSecurityConfig {
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(authorize -> authorize
.requestMatchers("/public").permitAll()
.requestMatchers("/user").hasRole("USER")
.anyRequest().authenticated()
)
.formLogin(login -> login
.permitAll()
);
return http.build();
}
@Bean
public UserDetailsService userDetailsService(PasswordEncoder passwordEncoder) {
UserDetails user = User.builder()
.username("john")
.password(passwordEncoder.encode("pass"))
.roles("USER")
.build();
return new InMemoryUserDetailsManager(user);
}
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
}
}Testing In-Memory Users
Run the previous application. Now try accessing:
http://localhost:8080/public: Should be accessible without login.http://localhost:8080/user: Should redirect to login. Use username 'john' and password 'pass'.http://localhost:8080/admin: Should redirect to login, then show 403 Forbidden even after logging in as 'john', because 'john' doesn't have the 'ADMIN' role.
Quick Check: Spring Security
You've learned about the basics of Spring Security and in-memory authentication. Let's test your understanding.
Lesson Summary
Great job! In this lesson, you've taken your first steps with Spring Security:
- Understood its purpose and core concepts (AuthN, AuthZ).
- Added the necessary dependency and observed default behavior.
- Learned about the Security Filter Chain.
- Implemented basic in-memory authentication with custom users and role-based URL protection.
Next, we'll explore how to handle authentication and authorization using databases and more advanced techniques!
AI チューターと学ぶ Java — 無料
ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。
- コース
- 21
- レッスン
- 84
よくある質問
「Spring Securityの基礎」レッスンは無料ですか?
はい。「Spring Securityの基礎」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Spring Boot 4 Complete Guideコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Spring Boot 4 Complete Guideコースには全4レッスンが含まれています。
「Spring Securityの基礎」で何を学びますか?
Spring Securityを設定し、そのアーキテクチャを理解して、基本的なインメモリ認証を実装します。 ブラウザで直接実行するハンズオンコードでSpring Boot 4 Complete Guideを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Spring Boot 4 Complete Guideを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのSpring Boot 4 Complete Guideは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。
「Spring Securityの基礎」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このSpring Boot 4 Complete Guideレッスンでコードを書いて実行できますか?
はい。すべてのSpring Boot 4 Complete Guideレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- Spring Securityの基礎
- 認証と認可
- JWTベースのセキュリティ
- OAuth2とソーシャルログインの統合