Spring Security 6 & JWT Authentication · レッスン

認証エラーとエントリーポイントへの対応

AuthenticationEntryPointとAccessDeniedHandlerを使い、JWTで保護されたSpringアプリが、トークンの欠落、無効、期限切れにどう応答するかをカスタマイズします。

レッスン 4/413 ステップ

「認証エラーとエントリーポイントへの対応」はCoddyKit上の無料Spring Security 6 & JWT Authenticationレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSpring Security 6 & JWT Authentication学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Spring Security 6 & JWT Authenticationコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Two Kinds of Security Failure

Spring Security distinguishes two failures:

  • Authentication failure (401): the user is not identified — missing or bad token
  • Authorization failure (403): the user is known but lacks permission

Each is handled by a different component.

The Default Behavior

Out of the box, a JWT app without a custom handler may redirect to a login page or return an HTML error. For a stateless API you usually want a clean JSON 401 instead.

AuthenticationEntryPoint

The AuthenticationEntryPoint is invoked when an unauthenticated user hits a protected endpoint. Implement commence to write your own response.

public interface AuthenticationEntryPoint {
    void commence(HttpServletRequest req,
                  HttpServletResponse res,
                  AuthenticationException ex);
}

Returning a JSON 401

Here the entry point sets a 401 status and writes a small JSON body, ideal for SPA and mobile clients.

res.setStatus(401);
res.setContentType('application/json');
res.getWriter().write("{\"error\":\"Unauthorized\"}");

AccessDeniedHandler

When an authenticated user lacks the required role, the AccessDeniedHandler runs. Implement handle to send a 403 response.

public interface AccessDeniedHandler {
    void handle(HttpServletRequest req,
                HttpServletResponse res,
                AccessDeniedException ex);
}

Returning a JSON 403

The denied handler mirrors the entry point but uses status 403 to signal a permission problem rather than a missing identity.

res.setStatus(403);
res.setContentType('application/json');
res.getWriter().write("{\"error\":\"Forbidden\"}");

Wiring Handlers into HttpSecurity

Register both handlers in your security configuration through exceptionHandling.

http.exceptionHandling(ex -> ex
    .authenticationEntryPoint(jwtEntryPoint)
    .accessDeniedHandler(jwtDeniedHandler));

Errors Inside the JWT Filter

If your JWT filter detects an expired or malformed token, do not throw a raw exception. Instead set a request attribute and let the entry point produce a consistent response.

catch (ExpiredJwtException e) {
    request.setAttribute('jwt_error', 'expired');
    filterChain.doFilter(request, response);
}

Including Helpful Details

A good error body helps clients react. Include a machine-readable code and a timestamp, but never leak internal stack traces or secrets.

res.getWriter().write(
  "{\"error\":\"token_expired\",\"status\":401}");

Consistent Error Shape

Keep every security error in the same JSON shape as your other API errors. Consistency lets the frontend handle 401, 403, and 500 with one error pipeline.

Testing the Handlers

Use MockMvc to confirm an unauthenticated request returns 401 and an under-privileged request returns 403 with the expected JSON.

mockMvc.perform(get('/api/secure'))
    .andExpect(status().isUnauthorized())
    .andExpect(jsonPath('$.error').value('Unauthorized'));

Quick Check

Test your understanding of security error handling.

Recap

You learned to customize JWT security errors:

  • AuthenticationEntryPoint handles 401 (unauthenticated)
  • AccessDeniedHandler handles 403 (forbidden)
  • Wire both via exceptionHandling
  • Return consistent JSON and never leak internals

Clear, predictable error responses make your secured API far easier to consume.

無料で開始

AI チューターと学ぶ Java — 無料

ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。

コース
12
レッスン
48

よくある質問

「認証エラーとエントリーポイントへの対応」レッスンは無料ですか?

はい。「認証エラーとエントリーポイントへの対応」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Spring Security 6 & JWT Authenticationコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Spring Security 6 & JWT Authenticationコースには全4レッスンが含まれています。

「認証エラーとエントリーポイントへの対応」で何を学びますか?

AuthenticationEntryPointとAccessDeniedHandlerを使い、JWTで保護されたSpringアプリが、トークンの欠落、無効、期限切れにどう応答するかをカスタマイズします。 ブラウザで直接実行するハンズオンコードでSpring Security 6 & JWT Authenticationを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Spring Security 6 & JWT Authenticationを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのSpring Security 6 & JWT Authenticationは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。

「認証エラーとエントリーポイントへの対応」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このSpring Security 6 & JWT Authenticationレッスンでコードを書いて実行できますか?

はい。すべてのSpring Security 6 & JWT Authenticationレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. JWT認証フローの設計
  2. カスタムJWTフィルターの実装
  3. AuthenticationManagerとProviderの統合
  4. 認証エラーとエントリーポイントへの対応
← Spring Security 6 & JWT Authenticationに戻る