Spring Security
Authentication and authorisation in depth: the filter chain and SecurityContext, form login, HTTP Basic and JWT, password encoding and hash migration, RBAC and method security, OAuth2 and OIDC, and CORS, CSRF and security testing.
The Filter Chain and SecurityContext
What FilterChainProxy actually does, the order filters run in, how the authenticated principal is stored per thread, and how to configure multiple chains.
Authentication: Form Login, HTTP Basic and JWT
Loading users with UserDetailsService, when sessions beat tokens, and a JWT filter built properly — including the validation steps that are easy to omit.
Password Encoding: BCrypt, Argon2 and Migrating Legacy Hashes
Why a fast hash is the wrong tool, how the work factor trades login latency for attack cost, and migrating MD5 hashes without forcing a password reset.
Authorisation: RBAC, Method Security and Expression Rules
URL rules versus method security, roles versus authorities, role hierarchies, and decisions that depend on the data rather than just the caller.
OAuth2 and OIDC: Resource Server, Client and Auth Server
What the flows actually are, configuring a resource server in two lines, the authorisation code flow with PKCE, and when to self-host an authorisation server.
CORS, CSRF and Testing Security
Two protections that answer different questions, why allowedOrigins('*') with credentials is rejected, and the tests that catch a misordered rule chain.