0Pricing
Spring Boot 4 Complete Guide · 课时

Spring Security 基础

设置 Spring Security,了解其架构,并实现基本的内存身份验证。

Spring Security 基础 是 CoddyKit 上的免费 Spring Boot 4 Complete Guide 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Boot 4 Complete Guide 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Boot 4 Complete Guide 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Welcome to Spring Security!

Securing web applications is crucial in today's digital world. Spring Security is a powerful and highly customizable authentication and access-control framework for Spring applications.

It provides robust security features, allowing you to protect your application from common vulnerabilities and control who can access what.

Why Spring Security?

Imagine building an online store. You need to:

  • Authenticate users: Verify a user's identity (login).
  • Authorize actions: Determine what a user can do (e.g., only admins can delete products).
  • Protect against threats: CSRF, XSS, session fixation.

Spring Security handles all these complex tasks, letting you focus on your application's core logic.

Adding the Security Dependency

To get started, you just need to add the spring-boot-starter-security dependency to your project. This starter brings in all necessary Spring Security modules.

For Maven, add this to your pom.xml:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

Default Security in Action

Once the dependency is added, Spring Boot automatically configures basic security. Try running this simple application:

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@RestController
public class SecurityApp {

    public static void main(String[] args) {
        SpringApplication.run(SecurityApp.class, args);
    }

    @GetMapping("/hello")
    public String hello() {
        return "Hello, Secured World!";
    }
}

Default Login & Password

When you run the previous code with the Spring Security dependency, you'll notice something:

  • Accessing /hello redirects you to a login page.
  • Spring Security generates a random password, printed in the console at startup.

The username is typically user, and the password is the generated one. This is basic, out-of-the-box security!

AuthN vs. AuthZ

Let's clarify two fundamental concepts:

  • Authentication (AuthN): Verifying who you are. This is typically done with credentials like username/password.
  • Authorization (AuthZ): Determining what you are allowed to do once authenticated. For example, a user might be authenticated, but only an 'admin' role can delete data.

Spring Security handles both!

The Security Filter Chain

At its core, Spring Security works by intercepting HTTP requests. It uses a series of filters, called the Security Filter Chain, to apply security logic.

When a request comes in, these filters perform tasks like authentication, authorization, session management, and more, before the request even reaches your controller.

Basic In-Memory Authentication

For simple applications or testing, you can define users directly in your application's memory. This is called in-memory authentication.

You'll configure a UserDetailsService bean that provides user details. Let's see how to define a custom user with a specific role.

Configuring In-Memory Users

Here's how to define a user 'john' with password 'pass' and role 'USER'. Remember to encode passwords!

package com.coddykit;

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.core.userdetails.User;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
import org.springframework.security.provisioning.InMemoryUserDetailsManager;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

@SpringBootApplication
@RestController
@EnableWebSecurity
public class SecurityConfigApp {

    public static void main(String[] args) {
        SpringApplication.run(SecurityConfigApp.class, args);
    }

    @GetMapping("/public")
    public String publicAccess() {
        return "This is a public page!";
    }

    @GetMapping("/user")
    public String userAccess() {
        return "Welcome, authenticated user!";
    }

    @Configuration
    static class WebSecurityConfig {

        @Bean
        public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
            http
                .authorizeHttpRequests(authorize -> authorize
                    .requestMatchers("/public").permitAll()
                    .requestMatchers("/user").hasRole("USER")
                    .anyRequest().authenticated()
                )
                .formLogin(login -> login
                    .permitAll()
                );
            return http.build();
        }

        @Bean
        public UserDetailsService userDetailsService(PasswordEncoder passwordEncoder) {
            UserDetails user = User.builder()
                .username("john")
                .password(passwordEncoder.encode("pass"))
                .roles("USER")
                .build();
            return new InMemoryUserDetailsManager(user);
        }

        @Bean
        public PasswordEncoder passwordEncoder() {
            return new BCryptPasswordEncoder();
        }
    }
}

Testing In-Memory Users

Run the previous application. Now try accessing:

  • http://localhost:8080/public: Should be accessible without login.
  • http://localhost:8080/user: Should redirect to login. Use username 'john' and password 'pass'.
  • http://localhost:8080/admin: Should redirect to login, then show 403 Forbidden even after logging in as 'john', because 'john' doesn't have the 'ADMIN' role.

Quick Check: Spring Security

You've learned about the basics of Spring Security and in-memory authentication. Let's test your understanding.

Lesson Summary

Great job! In this lesson, you've taken your first steps with Spring Security:

  • Understood its purpose and core concepts (AuthN, AuthZ).
  • Added the necessary dependency and observed default behavior.
  • Learned about the Security Filter Chain.
  • Implemented basic in-memory authentication with custom users and role-based URL protection.

Next, we'll explore how to handle authentication and authorization using databases and more advanced techniques!

常见问题解答

「Spring Security 基础」课时是免费的吗?

是的 — 「Spring Security 基础」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Boot 4 Complete Guide 课程的其余内容,请升级到 CoddyKit PRO。 Spring Boot 4 Complete Guide 课程共包含 4 节课。

「Spring Security 基础」这节课中我会学到什么?

设置 Spring Security,了解其架构,并实现基本的内存身份验证。 你通过在浏览器中直接运行的动手代码来练习 Spring Boot 4 Complete Guide,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Spring Boot 4 Complete Guide 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Spring Boot 4 Complete Guide 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。

「Spring Security 基础」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Spring Boot 4 Complete Guide 课中编写并运行代码吗?

能。每节 Spring Boot 4 Complete Guide 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. Spring Security 基础
  2. 身份验证与授权
  3. 基于 JWT 的安全机制
  4. OAuth2 与社交登录集成
← 返回 Spring Boot 4 Complete Guide