_ SPRING BOOT & SPRING SECURITY

Learn Spring Security OAuth|

The definitive guide to secure your application with OAuth2

Spring Security is, of course, the gold standard for implementing mature security in Java, and so is its great support for OAuth2.

However, there’s still a lot of confusion around what OAuth actually is. So, before going deeper into the advanced aspects of the standard and into implementation with Spring Security, we’ll start by building a clear understanding of the protocol.

Once we go over the basics, we’ll dive into common OAuth scenarios with Spring Security – from accessing JWT token attributes to testing OAuth clients and using OAuth in a microservices application.

Authentication icon
Authentication
Registration icon
Registration
Security Expressions icon
Security Expressions
Spring Security OAuth illustration
>_

Course Outline

~ 33 HOURS
01
Module 1 icon

Intro to OAuth2 and the OAuth2 Roles

4 LESSONS • ~ 2 HOURS
1.Intro to OAuth2 and the OAuth2 Roles
2.Picking the Right OAuth Grant Type/Flow to Use
3.The State of OAuth2 in Spring Security
4.Setting up the Project
02
Module 2 icon

The Basics of OAuth2

5 LESSONS • ~ 3 HOURS
1.The Authorization Code Flow
2.The Authorization Server with Keycloak
3.The New OAuth2 Client Support
4.The New Resource Server Support
5.JWT Support
03
Module 3 icon

OAuth2 Beyond the Basics - The Resource Server

8 LESSONS • ~ 8 HOURS
1.Basic Authorization with OAuth2
2.Verify and Validate Claims from the JWT
3.Accessing JWT Bearer Token Authentication Attributes
4.Accessing JWT Bearer Token Authentication Attributes Using SpEL
5.Custom Authorities from JWT Claims
6.Custom Validators for JWT Claims
7.Resource Server Multi-Tenancy Support
8.Resource Server Testing Support
04
Module 4 icon

OAuth2 Beyond the Basics - The Client

5 LESSONS • ~ 5 HOURS
1.The Client Configuration Under the Hood
2.New OAuth2 Social Login
3.Refreshing a Token
4.Testing OAuth2 Clients
5.The Authorization Code Flow with PKCE
05
Module 5 icon

OAuth2 Beyond the Basics - Deep Dives

9 LESSONS • ~ 11 HOURS
1.OAuth2 and SPAs (Theory)
2.OAuth2 and SPAs (Implementation)
3.Exploring JWS with OAuth2
4.Testing OAuth2 with REST-assured
5.OAuth2 and OpenID Connect
6.Logout with OAuth and OIDC
7.The Client Credentials Flow
8.Token Revocation
9.The Legacy Stack Authorization Server
06
Module 6 icon

Microservices, Spring Security and OAuth2

3 LESSONS • ~ 4 HOURS
1.OAuth Security Patterns in a Microservice Application
2.Sharing Principal Information in Microservices
3.Exploring Topologies – Gateway API as OAuth2 Client
Baeldung All Access Crown Icon

Access this course through Baeldung All Access

Our Full Course Library icon Our Full Course Library
IntelliJ Idea Ultimate (6 months free) icon IntelliJ Idea Ultimate (6 months free)
JProfiler (6 months free) icon JProfiler (6 months free)
Roadmap icon All Upcoming Courses (Roadmap)
Certificates of Completion icon Certificates of Completion
Multiple-Choice questions icon Multiple-Choice questions in Each Lesson
Pro Access icon Pro Access
Explore All Access Yearly or the Lifetime access

Do you have a team who would benefit from taking the course?

Here are our team licenses →
100% Money Back Guarantee Badge

20-Day Money Back Guarantee

I believe strongly in the quality of the course material to teach you the fundamentals of the library. I've put a lot of work and care into the material and hope you're going to use it and to develop and maintain your applications.

I confidently back all courses with a 20-Day Money Back Guarantee. I want you to dive in deep and experience the full wealth of this resource without hesitation.

If the material isn't a good fit, just contact me within 20 days of purchase and ask for a full refund for any single course package.