Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme
AuthenticationEntryPoint ve AccessDeniedHandler kullanarak JWT ile güvenceye alınmış Spring uygulamanızın eksik, geçersiz veya süresi dolmuş belirteçlere nasıl yanıt vereceğini özelleştirin.
Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme, CoddyKit'te ücretsiz bir Spring Security 6 & JWT Authentication dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Spring Security 6 & JWT Authentication öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Spring Security 6 & JWT Authentication kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Two Kinds of Security Failure
Spring Security distinguishes two failures:
- Authentication failure (401): the user is not identified — missing or bad token
- Authorization failure (403): the user is known but lacks permission
Each is handled by a different component.
The Default Behavior
Out of the box, a JWT app without a custom handler may redirect to a login page or return an HTML error. For a stateless API you usually want a clean JSON 401 instead.
AuthenticationEntryPoint
The AuthenticationEntryPoint is invoked when an unauthenticated user hits a protected endpoint. Implement commence to write your own response.
public interface AuthenticationEntryPoint {
void commence(HttpServletRequest req,
HttpServletResponse res,
AuthenticationException ex);
}Returning a JSON 401
Here the entry point sets a 401 status and writes a small JSON body, ideal for SPA and mobile clients.
res.setStatus(401);
res.setContentType('application/json');
res.getWriter().write("{\"error\":\"Unauthorized\"}");AccessDeniedHandler
When an authenticated user lacks the required role, the AccessDeniedHandler runs. Implement handle to send a 403 response.
public interface AccessDeniedHandler {
void handle(HttpServletRequest req,
HttpServletResponse res,
AccessDeniedException ex);
}Returning a JSON 403
The denied handler mirrors the entry point but uses status 403 to signal a permission problem rather than a missing identity.
res.setStatus(403);
res.setContentType('application/json');
res.getWriter().write("{\"error\":\"Forbidden\"}");Wiring Handlers into HttpSecurity
Register both handlers in your security configuration through exceptionHandling.
http.exceptionHandling(ex -> ex
.authenticationEntryPoint(jwtEntryPoint)
.accessDeniedHandler(jwtDeniedHandler));Errors Inside the JWT Filter
If your JWT filter detects an expired or malformed token, do not throw a raw exception. Instead set a request attribute and let the entry point produce a consistent response.
catch (ExpiredJwtException e) {
request.setAttribute('jwt_error', 'expired');
filterChain.doFilter(request, response);
}Including Helpful Details
A good error body helps clients react. Include a machine-readable code and a timestamp, but never leak internal stack traces or secrets.
res.getWriter().write(
"{\"error\":\"token_expired\",\"status\":401}");Consistent Error Shape
Keep every security error in the same JSON shape as your other API errors. Consistency lets the frontend handle 401, 403, and 500 with one error pipeline.
Testing the Handlers
Use MockMvc to confirm an unauthenticated request returns 401 and an under-privileged request returns 403 with the expected JSON.
mockMvc.perform(get('/api/secure'))
.andExpect(status().isUnauthorized())
.andExpect(jsonPath('$.error').value('Unauthorized'));Quick Check
Test your understanding of security error handling.
Recap
You learned to customize JWT security errors:
AuthenticationEntryPointhandles 401 (unauthenticated)AccessDeniedHandlerhandles 403 (forbidden)- Wire both via
exceptionHandling - Return consistent JSON and never leak internals
Clear, predictable error responses make your secured API far easier to consume.
Sıkça Sorulan Sorular
“Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme” dersi ücretsiz mi?
Evet — “Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Spring Security 6 & JWT Authentication kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Spring Security 6 & JWT Authentication kursu toplamda 4 dersten oluşur.
“Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme” dersinde ne öğreneceğim?
AuthenticationEntryPoint ve AccessDeniedHandler kullanarak JWT ile güvenceye alınmış Spring uygulamanızın eksik, geçersiz veya süresi dolmuş belirteçlere nasıl yanıt vereceğini özelleştirin. Spring Security 6 & JWT Authentication ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Spring Security 6 & JWT Authentication öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Spring Security 6 & JWT Authentication, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.
“Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Spring Security 6 & JWT Authentication dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Spring Security 6 & JWT Authentication dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- JWT Kimlik Doğrulama Akışını Tasarlama
- Özel JWT Filtresi Uygulama
- AuthenticationManager ve sağlayıcı entegrasyonu
- Kimlik Doğrulama Hatalarını ve Giriş Noktalarını Yönetme