spring-boot

5 posts.

5 min

A server that starts

Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.

  • spring-boot
  • spring-security
4 min

Hardening for production

Externalised issuer and CORS, health probes, and a persistent security audit trail.

  • security
  • spring-boot
4 min

Registration, errors and dev data

A registration API with validation, one consistent error format, and demo credentials that only exist in the dev profile.

  • spring-boot
  • validation
4 min

State that survives a restart

Move registered clients, authorizations and consent into PostgreSQL, with Flyway owning the schema.

  • postgresql
  • flyway
5 min

The plan

What we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out.

  • oauth2
  • oidc