0Pricing
Spring Security 6 & JWT Authentication · Ders

Özel kimlik doğrulama olayı işleme

Günlük kaydı, denetim veya diğer işlemleri uygulamak için kimlik doğrulama başarı ve başarısızlık olaylarına yönelik özel dinleyiciler oluşturun.

Özel kimlik doğrulama olayı işleme, CoddyKit'te ücretsiz bir Spring Security 6 & JWT Authentication dersidir. Bu, 4 dersinin 3. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Spring Security 6 & JWT Authentication öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Spring Security 6 & JWT Authentication kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

Intro to Auth Events

Welcome to Custom Authentication Event Handling! In Spring Security, many important actions, like a user logging in or failing to log in, trigger events.

These events are like signals that your application can 'listen' for. By listening, you can react to these security-related happenings.

  • Logging: Record who logged in and when.
  • Auditing: Track security-sensitive actions.
  • Custom Logic: Implement specific actions on success or failure (e.g., lock accounts after too many failed attempts).

Spring's Event System

Spring Framework has a powerful event publication and subscription model. Spring Security leverages this to publish various authentication-related events.

You can create custom components that 'listen' for these events and execute logic whenever they occur. This keeps your security logic separate and clean.

Key Authentication Events

Two of the most common and useful authentication events you'll encounter are:

  • AuthenticationSuccessEvent: Fired when a user successfully authenticates. This is perfect for logging successful logins or updating last login times.
  • AbstractAuthenticationFailureEvent: This is a base class for all authentication failure events. Specific failure types (e.g., bad credentials, disabled account) extend this. You can listen to the base class to catch all failures or specific subclasses.

Creating a Custom Listener

To create a listener, you typically use the @EventListener annotation on a method within a Spring component. Spring automatically detects these methods and registers them as event listeners.

The method's parameter type determines which event it will listen to. For example, a method with an AuthenticationSuccessEvent parameter will only be called when that specific event occurs.

Code: Success Listener Setup

Let's set up a simple Spring Boot application with in-memory authentication. This will allow us to trigger authentication events and see our listeners in action.

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;

@SpringBootApplication
@EnableWebSecurity
public class EventHandlingApp {

    public static void main(String[] args) {
        SpringApplication.run(EventHandlingApp.class, args);
    }

    @Bean
    public UserDetailsService userDetailsService() {
        UserDetails user = User.withDefaultPasswordEncoder()
            .username("user")
            .password("password")
            .roles("USER")
            .build();
        return new InMemoryUserDetailsManager(user);
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .anyRequest().authenticated()
            )
            .formLogin();
        return http.build();
    }
}

Code: Implementing Success Listener

Now, let's create our custom listener for successful authentication. We'll simply log a message when a user successfully logs in.

Save this as a new Java file (e.g., AuthenticationSuccessListener.java) in the same package as EventHandlingApp. Then, run EventHandlingApp and try to log in via a browser (e.g., localhost:8080 with user/password).

import org.springframework.context.event.EventListener;
import org.springframework.security.authentication.event.AuthenticationSuccessEvent;
import org.springframework.stereotype.Component;

@Component
public class AuthenticationSuccessListener {

    @EventListener
    public void handleAuthenticationSuccess(AuthenticationSuccessEvent event) {
        String username = event.getAuthentication().getName();
        System.out.println("SUCCESS: User '" + username + "' logged in successfully!");
        // You could also log full details, update a database, etc.
    }
}

Handling Authentication Failures

Just as important as successful logins are failed attempts. Spring Security provides AbstractAuthenticationFailureEvent and its subclasses to handle these scenarios.

By listening to this event, you can:

  • Log failed attempts for security auditing.
  • Implement brute-force protection (e.g., locking an account after N failures).
  • Trigger alerts for suspicious activity.

Code: Implementing Failure Listener

Let's add a listener for authentication failures. This listener will catch any type of failure and log the username and the reason for the failure.

Add this as another @Component or as a method in your existing AuthenticationSuccessListener. Try logging in with incorrect credentials to see it in action.

import org.springframework.context.event.EventListener;
import org.springframework.security.authentication.event.AbstractAuthenticationFailureEvent;
import org.springframework.stereotype.Component;

@Component
public class AuthenticationFailureListener {

    @EventListener
    public void handleAuthenticationFailure(AbstractAuthenticationFailureEvent event) {
        String username = event.getAuthentication().getName();
        String failureReason = event.getException().getMessage();
        System.err.println("FAILURE: User '" + username + "' failed to log in. Reason: " + failureReason);
        // You can check event.getException() for specific failure types
    }
}

Distinguishing Failure Types

AbstractAuthenticationFailureEvent is a parent class. For more granular control, you can listen to specific subclasses:

  • BadCredentialsEvent: Incorrect username/password.
  • DisabledExceptionEvent: User account is disabled.
  • LockedExceptionEvent: User account is locked.
  • AccountExpiredExceptionEvent: User account has expired.

You can create separate @EventListener methods for each or use instanceof checks within a single listener.

Custom Event Handling Check

You've learned how to create listeners for Spring Security authentication events. Let's check your understanding.

Recap: Event Handling

We've covered how Spring Security leverages Spring's event system to publish authentication-related events. You learned to:

  • Understand the purpose of authentication events for logging and auditing.
  • Use the @EventListener annotation to create custom listeners.
  • Handle AuthenticationSuccessEvent for successful logins.
  • Handle AbstractAuthenticationFailureEvent for various login failures.

By using these events, you gain powerful control and visibility into your application's authentication process.

Sıkça Sorulan Sorular

“Özel kimlik doğrulama olayı işleme” dersi ücretsiz mi?

Evet — “Özel kimlik doğrulama olayı işleme” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Spring Security 6 & JWT Authentication kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Spring Security 6 & JWT Authentication kursu toplamda 4 dersten oluşur.

“Özel kimlik doğrulama olayı işleme” dersinde ne öğreneceğim?

Günlük kaydı, denetim veya diğer işlemleri uygulamak için kimlik doğrulama başarı ve başarısızlık olaylarına yönelik özel dinleyiciler oluşturun. Spring Security 6 & JWT Authentication ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Spring Security 6 & JWT Authentication öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Spring Security 6 & JWT Authentication, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 3. dersidir.

“Özel kimlik doğrulama olayı işleme” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Spring Security 6 & JWT Authentication dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Spring Security 6 & JWT Authentication dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Çok faktörlü kimlik doğrulamayı uygulama
  2. API erişimini hız sınırlama
  3. Özel kimlik doğrulama olayı işleme
  4. Hesap Kilitleme ve Kaba Kuvvet Saldırısı Koruması
← Spring Security 6 & JWT Authentication Sayfasına Dön