Spring Boot
Capstone – Article 6: Password Encryption & Login Preparation (Expense Tracker)
By Utility Zone · 2026-01-27T18:32:07.674503
1. Introduction
Storing passwords in plain text is never acceptable.
Before implementing login and JWT:
- Passwords must be encrypted
- Authentication flow must be prepared correctly
In this article, we will:
- Encrypt passwords using BCrypt
- Update user creation flow
- Prepare groundwork for login & JWT
2. Why Password Encryption Matters
Plain-text passwords lead to:
- Severe security breaches
- Legal and compliance issues
- Immediate rejection in interviews
Industry standard: ✔ One-way hashing ✔ Salted hashes ✔ BCrypt
3. BCrypt Password Encoder
Spring Security provides:
BCryptPasswordEncoder
Features:
- Adaptive hashing
- Automatically handles salt
- Widely trusted
4. Creating Password Encoder Bean
4.1 Security Config (Temporary)
Create package:
com.example.expensetracker.config
Create class:
package com.example.expensetracker.config;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;
@Configuration
public class PasswordConfig {
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
}
This makes encoder available across the app.
5. Updating UserService to Encrypt Password
Update user creation logic:
@Service
public class UserService {
private final UserRepository userRepository;
private final PasswordEncoder passwordEncoder;
public UserService(UserRepository userRepository,
PasswordEncoder passwordEncoder) {
this.userRepository = userRepository;
this.passwordEncoder = passwordEncoder;
}
public UserResponse createUser(UserRequest request) {
User user = new User();
user.setName(request.getName());
user.setEmail(request.getEmail());
user.setPassword(passwordEncoder.encode(request.getPassword()));
user.setRole(request.getRole());
User savedUser = userRepository.save(user);
return mapToResponse(savedUser);
}
}
✔ Password is hashed before saving
✔ Original password is never stored
6. Verifying Encrypted Passwords
Create user using API.
Check database via H2 console:
SELECT email, password FROM USERS;
You should see:
- Long hashed string
- No readable password
This confirms encryption is working.
7. Preparing Login Flow (Conceptual)
Upcoming login flow:
- User submits email + password
- Fetch user by email
- Compare raw password with hashed password
- On success → generate JWT
BCrypt comparison:
passwordEncoder.matches(rawPassword, hashedPassword)
8. What NOT to Do
❌ Never decrypt passwords
❌ Never log passwords
❌ Never expose password in API
❌ Never reuse encryption logic manually
Always rely on PasswordEncoder.
9. Common Beginner Mistakes
❌ Saving raw password
❌ Double-encoding password
❌ Using weak hashing algorithms
❌ Encoding password during login
Encode only at registration, not at login.
10. Git Commit (Important)
Commit your changes:
git add .
git commit -m "Encrypt user passwords using BCrypt"
11. What You Should Have Now
At this point:
- Passwords are encrypted
- User creation is secure
- Login groundwork is ready
- App meets basic security standards
12. What’s Next?
➡ Capstone – Article 7: Login API & JWT Authentication
- Login endpoint
- JWT generation
- Securing APIs
Type Next when you’re ready 🔐🚀