Spring Security: Effectively secure your web apps, RESTful services, cloud apps, and microservice architectures - Softcover

Badr Nasslahsen

 
Image Not Available

Synopsis

Leverage the power of Spring Security 6 to protect your modern Java applications from hackers

Key Features

  • Architect solutions that leverage Spring Security while remaining loosely coupled
  • Implement authentication and authorization with SAML2, OAuth 2, hashing, and encryption algorithms
  • Integrate Spring Security with technologies such as microservices, Kubernetes, the cloud, and GraalVM native images
  • Purchase of the print or Kindle book includes a free PDF eBook

Book Description

Knowing that experienced hackers are constantly on the prowl to attack your apps can make security one of the most challenging concerns of creating an app. The complexity of properly securing an app is compounded when you must also integrate this factor with legacy code, new technologies, and other frameworks. This book will help you easily secure your Java apps with Spring Security, a trusted and highly customizable authentication and access control framework.

The book starts by showing you how to implement different authentication mechanisms before demonstrating how to properly restrict access to your app. You’ll then cover tips for integrating Spring Security with popular web frameworks such as Thymeleaf. The book also features an example of how Spring Security defends against session fixation, moves into concurrency control, and how you can use session management for administrative functions. This fourth edition aligns with Java 17/21 and Spring Security 6, covering advanced security scenarios for RESTful web services and microservices. This ensures you gain a complete understanding of the issues surrounding stateless authentication and discover a concise approach to solving those issues.

By the end of this book, you’ll be able to integrate Spring Security 6 with GraalVM native images seamlessly, from start to finish.

What you will learn

  • Understand common security vulnerabilities and how to resolve them
  • Implement authentication and authorization and learn how to map users to roles
  • Integrate Spring Security with LDAP, Kerberos, SAML 2, OpenID, and OAuth
  • Get to grips with the security challenges of RESTful web services and microservices
  • Configure Spring Security to use Spring Data for authentication
  • Integrate Spring Security with Spring Boot, Spring Data, and web applications
  • Protect against common vulnerabilities like XSS, CSRF, and Clickjacking

Who this book is for

If you’re a Java web developer or an architect with fundamental knowledge of Java 17/21, web services, and the Spring Framework, this book is for you. No previous experience with Spring Security is needed to get started with this book.

Table of Contents

  1. Anatomy of an Unsafe Application
  2. Getting Started with Spring Security
  3. Custom Authentication
  4. JDBC-based Authentication
  5. Authentication with Spring Data
  6. LDAP Directory Services
  7. Remember-me Services
  8. Client Certificate Authentication with TLS
  9. Opening up to OAuth 2
  10. SAML 2 Support
  11. Fine-Grained Access Control
  12. Access Control Lists
  13. Custom Authorization
  14. Session Management
  15. Additional Spring Security Features
  16. Migration to Spring Security 6
  17. Microservice Security with OAuth 2 and JSON Web Tokens
  18. Single Sign-On with the Central Authentication Service
  19. Build GraalVM Native Images
  20. Appendix – Additional Reference Material

"synopsis" may belong to another edition of this title.

About the Author

Badr Nasslahsen is a lead security and cloud architect with over 17 years of experience. He holds an executive master's degree from Ecole Centrale Paris and an engineering degree from Telecom SudParis. He is an Oracle Certified Java SE 11 Professional, CISSP, TOGAF, CKA, and Scrum Master. Badr has extensive experience with public cloud providers such as AWS, Azure, GCP, Oracle, and IBM. He is also the author of the springdoc-openapi project.

"About this title" may belong to another edition of this title.

  • PublisherPackt Publishing
  • Publication date2024
  • ISBN 10 183546050X
  • ISBN 13 9781835460504
  • BindingPaperback
  • LanguageEnglish
  • Edition number4
  • Number of pages596