Spring Boot

Capstone – Article 6: Password Encryption & Login Preparation (Expense Tracker)

By Utility Zone · 2026-01-27T18:32:07.674503

1. Introduction

Storing passwords in plain text is never acceptable.

Before implementing login and JWT:

  • Passwords must be encrypted
  • Authentication flow must be prepared correctly

In this article, we will:

  • Encrypt passwords using BCrypt
  • Update user creation flow
  • Prepare groundwork for login & JWT

2. Why Password Encryption Matters

Plain-text passwords lead to:

  • Severe security breaches
  • Legal and compliance issues
  • Immediate rejection in interviews

Industry standard: ✔ One-way hashing ✔ Salted hashes ✔ BCrypt


3. BCrypt Password Encoder

Spring Security provides:

BCryptPasswordEncoder

Features:

  • Adaptive hashing
  • Automatically handles salt
  • Widely trusted

4. Creating Password Encoder Bean

4.1 Security Config (Temporary)

Create package:

com.example.expensetracker.config

Create class:

package com.example.expensetracker.config;

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.crypto.password.PasswordEncoder;

@Configuration
public class PasswordConfig {

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}

This makes encoder available across the app.


5. Updating UserService to Encrypt Password

Update user creation logic:

@Service
public class UserService {

    private final UserRepository userRepository;
    private final PasswordEncoder passwordEncoder;

    public UserService(UserRepository userRepository,
                       PasswordEncoder passwordEncoder) {
        this.userRepository = userRepository;
        this.passwordEncoder = passwordEncoder;
    }

    public UserResponse createUser(UserRequest request) {

        User user = new User();
        user.setName(request.getName());
        user.setEmail(request.getEmail());
        user.setPassword(passwordEncoder.encode(request.getPassword()));
        user.setRole(request.getRole());

        User savedUser = userRepository.save(user);
        return mapToResponse(savedUser);
    }
}

✔ Password is hashed before saving
✔ Original password is never stored


6. Verifying Encrypted Passwords

Create user using API.

Check database via H2 console:

SELECT email, password FROM USERS;

You should see:

  • Long hashed string
  • No readable password

This confirms encryption is working.


7. Preparing Login Flow (Conceptual)

Upcoming login flow:

  1. User submits email + password
  2. Fetch user by email
  3. Compare raw password with hashed password
  4. On success → generate JWT

BCrypt comparison:

passwordEncoder.matches(rawPassword, hashedPassword)

8. What NOT to Do

❌ Never decrypt passwords
❌ Never log passwords
❌ Never expose password in API
❌ Never reuse encryption logic manually

Always rely on PasswordEncoder.


9. Common Beginner Mistakes

❌ Saving raw password
❌ Double-encoding password
❌ Using weak hashing algorithms
❌ Encoding password during login

Encode only at registration, not at login.


10. Git Commit (Important)

Commit your changes:

git add .
git commit -m "Encrypt user passwords using BCrypt"

11. What You Should Have Now

At this point:

  • Passwords are encrypted
  • User creation is secure
  • Login groundwork is ready
  • App meets basic security standards

12. What’s Next?

➡ Capstone – Article 7: Login API & JWT Authentication

  • Login endpoint
  • JWT generation
  • Securing APIs

Type Next when you’re ready 🔐🚀