Spring Boot

Article 13: Spring Security Basics

By Utility Zone · 2026-01-27T18:29:18.53925

1. Introduction

Security is not optional.

Any real backend must answer:

  • Who are you? (Authentication)
  • What are you allowed to do? (Authorization)

Spring Security is powerful, flexible — and often confusing for beginners. This article builds clear fundamentals before advanced topics like JWT.


2. Authentication vs Authorization

Authentication

✔ Verifies identity

  • Username/password
  • Token
  • OAuth

Authorization

✔ Verifies permissions

  • Roles
  • Access rules

Authentication comes before authorization.


3. What Is Spring Security?

Spring Security:

  • Is a filter-based framework
  • Intercepts HTTP requests
  • Applies security rules before controller logic

Once enabled, everything is secured by default.


4. Adding Spring Security Dependency

Add to pom.xml:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-security</artifactId>
</dependency>

Restart the app.


5. Default Spring Security Behavior

After adding the dependency:

  • All endpoints are secured
  • Browser shows login popup
  • Default user is user
  • Password is printed in console

Example console log:

Using generated security password: a3f9c1b2...

6. Testing Secured Endpoints

Open:

http://localhost:8080/hello

You’ll see:

  • Login prompt (HTTP Basic)

This proves Spring Security is active.


7. How Spring Security Works (High Level)

Request flow:

Client → Security Filters → Controller → Response

Key concept:

  • Filters decide access
  • Controllers never see unauthorized requests

8. Custom Security Configuration

8.1 Creating Security Config Class

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {

        http
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/public/**").permitAll()
                .anyRequest().authenticated()
            )
            .httpBasic();

        return http.build();
    }
}

9. Securing Specific Endpoints

Public endpoint:

/public/hello

Protected endpoint:

/users

Spring enforces access automatically.


10. In-Memory Authentication (For Learning)

@Bean
public UserDetailsService userDetailsService() {

    UserDetails user = User.withUsername("admin")
            .password("{noop}password")
            .roles("ADMIN")
            .build();

    return new InMemoryUserDetailsManager(user);
}

✔ Good for demos
❌ Not for production


11. CSRF Explained (Brief)

CSRF protects against:

  • Unauthorized form submissions

For REST APIs:

csrf.disable()

For browser-based apps: ✔ Enable CSRF


12. Common Beginner Mistakes

❌ Forgetting to permit Swagger endpoints
❌ Blocking all APIs accidentally
❌ Confusing roles & authorities
❌ Hardcoding passwords


13. Best Practices

✔ Start simple
✔ Secure only required endpoints first
✔ Use method-level security later
✔ Never write your own crypto


14. What You Should Understand Before Moving On

You should now know:

  • Authentication vs Authorization
  • How Spring Security intercepts requests
  • How to secure APIs
  • How to configure basic security

15. What’s Next?

➡ Article 14: JWT Authentication

  • Token-based security
  • Login API
  • Stateless authentication

Type Next when you’re ready.