security

3 posts.

4 min

Accounts, passwords and lockout

User administration, self-service and admin password changes, and a temporary lockout after repeated failed logins.

  • spring-security
  • security
4 min

Hardening for production

Externalised issuer and CORS, health probes, and a persistent security audit trail.

  • security
  • spring-boot
4 min

Revoking a JWT

Token revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately.

  • oauth2
  • jwt