Spring Boot
Article 13: Spring Security Basics
By Utility Zone · 2026-01-27T18:29:18.53925
1. Introduction
Security is not optional.
Any real backend must answer:
- Who are you? (Authentication)
- What are you allowed to do? (Authorization)
Spring Security is powerful, flexible — and often confusing for beginners. This article builds clear fundamentals before advanced topics like JWT.
2. Authentication vs Authorization
Authentication
✔ Verifies identity
- Username/password
- Token
- OAuth
Authorization
✔ Verifies permissions
- Roles
- Access rules
Authentication comes before authorization.
3. What Is Spring Security?
Spring Security:
- Is a filter-based framework
- Intercepts HTTP requests
- Applies security rules before controller logic
Once enabled, everything is secured by default.
4. Adding Spring Security Dependency
Add to pom.xml:
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>
Restart the app.
5. Default Spring Security Behavior
After adding the dependency:
- All endpoints are secured
- Browser shows login popup
- Default user is
user - Password is printed in console
Example console log:
Using generated security password: a3f9c1b2...
6. Testing Secured Endpoints
Open:
http://localhost:8080/hello
You’ll see:
- Login prompt (HTTP Basic)
This proves Spring Security is active.
7. How Spring Security Works (High Level)
Request flow:
Client → Security Filters → Controller → Response
Key concept:
- Filters decide access
- Controllers never see unauthorized requests
8. Custom Security Configuration
8.1 Creating Security Config Class
@Configuration
@EnableWebSecurity
public class SecurityConfig {
@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.csrf(csrf -> csrf.disable())
.authorizeHttpRequests(auth -> auth
.requestMatchers("/public/**").permitAll()
.anyRequest().authenticated()
)
.httpBasic();
return http.build();
}
}
9. Securing Specific Endpoints
Public endpoint:
/public/hello
Protected endpoint:
/users
Spring enforces access automatically.
10. In-Memory Authentication (For Learning)
@Bean
public UserDetailsService userDetailsService() {
UserDetails user = User.withUsername("admin")
.password("{noop}password")
.roles("ADMIN")
.build();
return new InMemoryUserDetailsManager(user);
}
✔ Good for demos
❌ Not for production
11. CSRF Explained (Brief)
CSRF protects against:
- Unauthorized form submissions
For REST APIs:
csrf.disable()
For browser-based apps: ✔ Enable CSRF
12. Common Beginner Mistakes
❌ Forgetting to permit Swagger endpoints
❌ Blocking all APIs accidentally
❌ Confusing roles & authorities
❌ Hardcoding passwords
13. Best Practices
✔ Start simple
✔ Secure only required endpoints first
✔ Use method-level security later
✔ Never write your own crypto
14. What You Should Understand Before Moving On
You should now know:
- Authentication vs Authorization
- How Spring Security intercepts requests
- How to secure APIs
- How to configure basic security
15. What’s Next?
➡ Article 14: JWT Authentication
- Token-based security
- Login API
- Stateless authentication
Type Next when you’re ready.