Entendendo a cadeia de filtros do Spring Security
Explore os bastidores do Spring Security 6 para entender como a cadeia de filtros de servlet processa cada solicitação e onde a autenticação se encaixa.
Entendendo a cadeia de filtros do Spring Security é uma aula grátis de Spring Security 6 & JWT Authentication no CoddyKit. Esta é a aula 4 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Spring Security 6 & JWT Authentication, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Spring Security 6 & JWT Authentication inclui 4 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
How Requests Get Secured
So how does every request actually get checked? The security filter chain — a series of servlet filters Spring slots in before your controllers.
What Is a Servlet Filter?
A servlet Filter intercepts HTTP requests and responses before they reach your code. Spring Security is built almost entirely from these filters.
The DelegatingFilterProxy
The real servlet filter, DelegatingFilterProxy, hands each request to a Spring-managed bean — bridging the servlet world and the Spring context.
The FilterChainProxy
Behind that proxy sits FilterChainProxy, which holds one or more SecurityFilterChain instances and routes each request to the one that matches.
Key Filters in Order
Filters run in a fixed order: SecurityContextHolderFilter loads context, the auth filter handles login, and AuthorizationFilter enforces access rules.
Defining a SecurityFilterChain Bean
In Spring Security 6 you configure everything by declaring a SecurityFilterChain bean — the modern replacement for WebSecurityConfigurerAdapter. See below.
@Bean
SecurityFilterChain chain(HttpSecurity http) throws Exception {
http.authorizeHttpRequests(a -> a.anyRequest().authenticated())
.formLogin(Customizer.withDefaults());
return http.build();
}Where the SecurityContext Lives
After login, the Authentication is stored in the SecurityContext and stays reachable via SecurityContextHolder for the rest of the request.
Authentication auth = SecurityContextHolder.getContext().getAuthentication();Permitting Some Paths
Let public paths through while securing the rest — all on the same chain. The code uses permitAll() for /public and authenticated() for everything else.
http.authorizeHttpRequests(a -> a
.requestMatchers('/public/**').permitAll()
.anyRequest().authenticated());Multiple Filter Chains
Register several SecurityFilterChain beans with securityMatcher so API and web paths get different rules. The first matching chain wins.
http.securityMatcher('/api/**');Adding a Custom Filter
Slot your own filter at a precise position with addFilterBefore — the foundation for the JWT processing you'll build later in this course.
http.addFilterBefore(myFilter, UsernamePasswordAuthenticationFilter.class);Why This Matters
Knowing the chain explains why ordering matters, where auth versus authz happens, and exactly where a custom JWT filter has to plug in.
Quick Check
In Spring Security 6, how do you define your security configuration?
Recap
Recap: requests flow DelegatingFilterProxy to FilterChainProxy to SecurityFilterChain; filters run in order, auth then authz, and addFilterBefore inserts custom ones.
Perguntas Frequentes
A aula “Entendendo a cadeia de filtros do Spring Security” é grátis?
Sim — o texto completo de “Entendendo a cadeia de filtros do Spring Security” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Spring Security 6 & JWT Authentication, atualize para CoddyKit PRO. O curso de Spring Security 6 & JWT Authentication inclui 4 aulas no total.
O que vou aprender em “Entendendo a cadeia de filtros do Spring Security”?
Explore os bastidores do Spring Security 6 para entender como a cadeia de filtros de servlet processa cada solicitação e onde a autenticação se encaixa. Você pratica Spring Security 6 & JWT Authentication com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar Spring Security 6 & JWT Authentication?
Nenhuma experiência prévia é necessária. Spring Security 6 & JWT Authentication no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 4 de 4.
Quanto tempo leva a aula “Entendendo a cadeia de filtros do Spring Security”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de Spring Security 6 & JWT Authentication?
Sim. Cada aula de Spring Security 6 & JWT Authentication inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Introdução ao Spring Security 6
- Configuração do projeto e dependências
- Autenticação de usuários em memória
- Entendendo a cadeia de filtros do Spring Security