spring-security

5 posts.

5 min

A server that starts

Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.

  • spring-boot
  • spring-security
4 min

Accounts, passwords and lockout

User administration, self-service and admin password changes, and a temporary lockout after repeated failed logins.

  • spring-security
  • security
4 min

ID tokens and UserInfo

Scope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them.

  • oidc
  • jwt
5 min

Managing clients and scopes

ADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token.

  • spring-security
  • oauth2
5 min

Users in the database

Replace the in-memory user with JPA entities, roles, and a database-backed UserDetailsService that accepts username or email.

  • spring-security
  • jpa