Spring Boot provides a set of auto-configuration classes to simplify security configuration. Starting with Spring Boot 3.2, some methods and classes have been deprecated or replaced, and the security configuration has been streamlined. In this tutorial, we'll walk through the process of setting up security in a Spring Boot 3.2 application using the new recommended approach.
Prerequisites
- JDK 17 or later
- Maven or Gradle
- IDE (IntelliJ IDEA, Eclipse, etc.)
Step 1: Set Up a Spring Boot Project
1.1 Create a New Spring Boot Project
Use Spring Initializr to create a new project with the following dependencies:
- Spring Web
- Spring Security
Download and unzip the project, then open it in your IDE.
1.2 Configure application.properties
Set up the application properties for your project. This file is located in the src/main/resources
directory.
# src/main/resources/application.properties server.port=8080
Step 2: Implement Security Configuration
2.1 Create a Security Configuration Class
In Spring Boot 3.2, the way to configure security has changed. The authorizeRequests()
method has been replaced with authorizeHttpRequests()
, and antMatchers()
has been replaced with requestMatchers()
. We will use these new methods to set up our security configuration.
package com.example.demo.config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfig { @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests((requests) -> requests .requestMatchers("/public/**").permitAll() .anyRequest().authenticated() ) .formLogin((form) -> form .loginPage("/login") .permitAll() ) .logout((logout) -> logout .permitAll() ); return http.build(); } }
Explanation:
@Configuration
: Marks this class as a source of bean definitions. SecurityFilterChain
: Configures the security filter chain. authorizeHttpRequests()
: Replaces the deprecated authorizeRequests()
. requestMatchers()
: Replaces the deprecated antMatchers()
for URL matching. formLogin()
: Configures form-based authentication. logout()
: Configures the logout functionality.
2.2 Create a Custom Login Page
Create a custom login page in the src/main/resources/templates
directory. If you're not using Thymeleaf, adjust the path and file type as necessary.
<!-- src/main/resources/templates/login.html --> <!DOCTYPE html> <html xmlns:th="http://www.thymeleaf.org"> <head> <title>Login</title> </head> <body> <h1>Login</h1> <form th:action="@{/login}" method="post"> <div> <label>Username:</label> <input type="text" name="username"/> </div> <div> <label>Password:</label> <input type="password" name="password"/> </div> <div> <button type="submit">Login</button> </div> </form> </body> </html>
2.3 Create a Controller for Public Access
Create a controller to handle public and secure endpoints.
package com.example.demo.controller; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; @RestController public class DemoController { @GetMapping("/public") public String publicEndpoint() { return "This is a public endpoint."; } @GetMapping("/secure") public String secureEndpoint() { return "This is a secure endpoint."; } }
Explanation:
@RestController
: Marks the class as a REST controller. @GetMapping("/public")
: Maps GET requests to the publicEndpoint
method. @GetMapping("/secure")
: Maps GET requests to the secureEndpoint
method.
Step 3: Running and Testing the Application
3.1 Run the Application
Run the Spring Boot application using your IDE or the command line:
./mvnw spring-boot:run
3.2 Test the Security Configuration
-
Open your browser and navigate to http://localhost:8080/public
. You should see the message "This is a public endpoint."
-
Navigate to http://localhost:8080/secure
. You should be redirected to the login page.
-
Log in using the default credentials provided by Spring Security (user
and a generated password printed in the console).
-
After logging in, you should see the message "This is a secure endpoint."
Step 4: Customizing User Details
4.1 Create a Custom UserDetailsService
To provide custom user details, you can implement the UserDetailsService
interface.
package com.example.demo.service; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.core.userdetails.User; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.provisioning.InMemoryUserDetailsManager; @Configuration public class UserDetailsServiceConfig { @Bean public UserDetailsService userDetailsService() { var userDetailsService = new InMemoryUserDetailsManager(); var user = User.withUsername("user") .password("{noop}password") // {noop} indicates no encoding .roles("USER") .build(); userDetailsService.createUser(user); return userDetailsService; } }
Explanation:
InMemoryUserDetailsManager
: An implementation of UserDetailsService
that stores user details in memory. User.withUsername("user")
: Creates a user with the username "user" and password "password" (no encoding).
4.2 Update Security Configuration
Update the SecurityConfig
class to use the custom UserDetailsService
.
package com.example.demo.config; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.core.userdetails.UserDetailsService; import org.springframework.security.web.SecurityFilterChain; @Configuration public class SecurityConfig { private final UserDetailsService userDetailsService; public SecurityConfig(UserDetailsService userDetailsService) { this.userDetailsService = userDetailsService; } @Bean public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception { http .authorizeHttpRequests((requests) -> requests .requestMatchers("/public/**").permitAll() .anyRequest().authenticated() ) .formLogin((form) -> form .loginPage("/login") .permitAll() ) .logout((logout) -> logout .permitAll() ) .userDetailsService(userDetailsService); return http.build(); } }
Explanation:
- The
SecurityConfig
constructor now takes a UserDetailsService
parameter. - The
userDetailsService
method is added to the security filter chain configuration.
Conclusion
In this tutorial, you have learned how to set up and configure security in a Spring Boot 3.2 application using the new recommended approach. We covered:
- Creating a custom security configuration class.
- Setting up a custom login page.
- Creating a controller for public and secure endpoints.
- Running and testing the security configuration.
- Customizing user details with a custom
UserDetailsService
.
By following these steps, you can secure your Spring Boot applications and control access to different parts of your application.
Related Spring Boot Source Code Examples
Spring Boot Security Login REST API Example Spring Boot Security Login and Registration REST API Role-based Authorization using Spring Boot and Spring Security Spring Boot JWT Authentication and Authorization Example Spring Boot Security JWT Example - Login REST API with JWT Authentication Spring Boot DTO Example Spring Boot DTO ModelMapper Example @GetMapping Spring Boot Example @PostMapping Spring Boot Example @PutMapping Spring Boot Example @DeleteMapping Spring Boot Example @PatchMapping Spring Boot Example @SpringBootApplication - Spring Boot Spring Boot Hello World REST API Example Spring Boot REST API returns Java Bean Create Spring Boot REST API returns List Spring Boot REST API with Path Variable Spring Boot REST API with Request Param Spring Boot Hibernate MySQL CRUD REST API Tutorial Spring Boot Real-Time Project Development using Spring MVC + Spring Security + Thymeleaf and MySQL Database Spring Boot Tutorial - User Login and Registration Backend + Email Verification Spring Boot JUnit and Mockito Example - Service Layer Testing Spring Professional Certification Cost Spring Boot Validate JSON Request Body Spring Boot One to Many CRUD Example | REST Controller Spring Boot Project with Controller Layer + Service Layer + Repository/DAO Layer Spring Boot Reactive MongoDB CRUD Example - WebFlux Spring Boot Amazon S3 - File Upload Download Delete Example Spring Boot RabbitMQ Publisher and Consumer Example Free Spring Boot Open Source Projects for Learning Purposes Spring Boot + Microsoft SQL Server + Hibernate Example Spring Boot Hibernate Thymeleaf MySQL CRUD Example Spring Boot CRUD Example with Spring MVC, Spring Data JPA, ThymeLeaf, Hibernate, MySQL Spring Boot Hibernate RESTful GET POST PUT and DELETE API Tutorial Best YouTube Channels to learn Spring Boot React Spring Boot Example Spring Boot Groovy Thymeleaf Example Tutorial Spring Boot Scala Thymeleaf Example Tutorial Spring Boot Hibernate DAO with MySQL Database Example Spring Boot PostgreSQL CRUD Example Spring Boot CRUD Example with MySQL Spring Boot Starter Parent Spring Boot JdbcTemplate Example Spring Boot PayPal Payment Gateway Integration Example Create Spring Boot REST API How to Create Spring Boot Application Using Maven How to Create Spring Boot Application Using Gradle How to Use Thymeleaf in a Spring Boot Web Application? How to Enable CORS in a Spring Boot Application? Spring Boot + Angular 8 CRUD Example Spring Boot + Angular 9 CRUD Example Spring Boot + Angular + WebSocket Example Spring Boot CRUD Application with Thymeleaf Spring Boot ReactJS CRUD Project - Employee Management App | GitHub Spring Petclinic ReactJS Project | GitHub Spring Boot React JWT Authentication Example Spring Boot React Basic Authentication Example CRUD Example using Spring Boot + Angular + MySQL Spring Boot + React + Redux CRUD Example Spring Boot Project - Sagan Spring Boot Project - ReactJS Spring Boot CRUD Full Stack Application - GitHub Spring Boot Project - Spring Initializr Spring Boot + Angular Project - Employee Management System Spring Boot Thymeleaf Project - Employee Management System Spring Boot MVC Project - Blogs Aggregator Spring Boot Project - Spring Petclinic | GitHub Spring Boot, Spring Cloud Microservice Project - PiggyMetrics | GitHub Spring Boot, Spring Security, JWT, React, and Ant Design - Polling App | GitHub Spring Boot Microservice Project - Shopping Cart App | GitHub Spring Boot, Spring Cloud Microservice Project - Spring Petclinic App | GitHub Microservices with Spring Cloud Project | GitHub Spring Boot Angular Petclinic Project | GitHub Spring Boot Angular Project - BookStore App | GitHub React Springboot Microservices Project | GitHub Spring Boot Microservices, Spring Cloud, and React Project - BookStoreApp | GitHub Spring Boot + Spring Security + JWT Example Spring Boot Hibernate Assign UUID Identifiers Example Spring Boot Angular Project - Reddit Clone Application Spring Boot Step-by-Step Example Spring Boot Starters List Spring Boot E-Commerce Project - Shopizer Spring Data JPA - save() Method Example Spring Data JPA - saveAll() Method Example Spring Data JPA - findById() Method Example Spring Data JPA - findAll() Method Example Spring Data JPA - count() Method Example Spring Data JPA - deleteById() Method Example Spring Data JPA - delete() Method Example Spring Data JPA - deleteAll() Method Example Spring Data JPA - Distinct Query Method Example Spring Data JPA - GreaterThan Query Method Example Spring Data JPA - LessThan Query Method Example Spring Data JPA - Containing Query Method Example Spring Data JPA - Like Query Method Example Spring Data JPA - Between Query Method Example Spring Data JPA - Date Range Between Query Method Example Spring Data JPA - In Clause Query Method Example Unit Test Spring Boot GET REST API using JUnit and Mockito Unit Test Spring Boot POST REST API using JUnit and Mockito Unit Test Spring Boot PUT REST API using JUnit and Mockito Unit Test Spring Boot DELETE REST API using JUnit and Mockito Create REST Client using WebClient for Spring Boot CRUD REST API Spring Boot WebClient GET Request with Parameters Spring Boot WebClient POST Request Example Spring Boot WebClient PUT Request Example Spring Boot WebClient DELETE Request Example Spring Boot RestClient GET Request Example Spring Boot RestClient POST Request Example Spring Boot RestClient PUT Request Example Spring Boot RestClient Delete Request Example Spring Core Annotations with Examples
Spring Boot @Component Example Spring Boot @Autowired Example Spring Boot @Qualifier Example Spring Boot @Primary Example Spring Boot @Bean Example Spring Boot @Lazy Example Spring Boot @Scope Example Spring Boot @PropertySource Example Spring Boot @Transactional Example Spring Boot @Configuration Example Spring Boot @ComponentScan Example Spring Boot @Profile Example Spring Boot @Cacheable Example Spring Boot @DependsOn Example Spring Boot @RestController Example Spring Boot @ResponseBody Example Spring Boot @GetMapping Example Spring Boot @PostMapping Example Spring Boot @PutMapping Example Spring Boot @DeleteMapping Example Spring Boot @PatchMapping Example Spring Boot @PathVariable Example Spring Boot @ResponseStatus Example Spring Boot @Service Example Spring Boot @Repository Example Spring Boot @RequestParam Example Spring Boot @SessionAttribute Example Spring Boot @RequestBody Example Spring Boot @ExceptionHandler Example Spring Boot @InitBinder Example Spring Boot @ModelAttribute Example Spring Boot @RequestMapping Example Spring Boot @CrossOrigin Example Spring Boot @ControllerAdvice Example Spring Boot @RestControllerAdvice Example Spring Boot @SpringBootApplication Example Spring Boot @EnableAutoConfiguration Example Spring Boot @ConditionalOnClass Example Spring Boot @SpringBootConfiguration Example Spring Boot @ConditionalOnProperty Example Spring Boot @ConditionalOnWebApplication Example Spring Boot @ConfigurationProperties Example Spring Boot @Async Example Spring Boot @Scheduled Example Spring Boot @SpringBootTest Example Spring Boot @WebMvcTest Example Spring Boot @DataJpaTest Example Spring Boot @EnableDiscoveryClient Example Spring Boot @EnableFeignClients Example Spring Boot @RefreshScope Example Spring Boot @LoadBalanced Example Spring Boot @Query Example Spring Boot @Modifying Example Spring Boot @Param Example Spring Boot JPA @Transient Example Spring Boot JPA @Enumerated Example Spring Boot JPA @Temporal Example Spring Boot @CreatedBy Example Spring Boot @LastModifiedDate Example Spring Boot @IdClass Example Spring Boot Spring Security
Comments
Post a Comment