Skip to content
JavaAgentic

Type at least two characters. Try “RAG”, “pgvector” or “tool calling”.

From basic authentication to zero-trust architecture

The Spring Security Mastery Roadmap

Forty topics covering every authentication mechanism, every authorisation model, every major attack class and the compliance frameworks that govern them — ending in a zero-trust platform design.

Who it is for: Backend engineers responsible for authentication, authorisation and compliance

Your progress

Loading…

0%

Spring Security Foundations

15 topics · 15 published

  1. 1
    Spring Security Architecture Deep Dive

    Security Filter Chain · SecurityContextHolder · AuthenticationManager · UserDetailsService · GrantedAuthority

  2. 2
    Password Management & Encoding

    BCrypt & Argon2 · DelegatingPasswordEncoder · Hash Migration · Passay Rules · Breached-Password Checks

  3. 3
    HTTP Basic & Form-Based Authentication

    BasicAuthenticationFilter · formLogin() · Custom Login Pages · Logout Handling · Success & Failure Handlers

  4. 4
    In-Memory & JDBC Authentication

    InMemoryUserDetailsManager · JdbcUserDetailsManager · Custom Queries · Schema Design · Admin Seeding

  5. 5
    JWT Authentication Deep Dive

    JWT Structure · HS256 vs RS256 · JWKS & Key Rotation · alg=none & Key Confusion · Token Revocation

  6. 6
    OAuth 2.0 — The Complete Guide

    Authorization Code + PKCE · Client Credentials · Refresh Rotation · Token Introspection · OAuth 2.1 Changes

  7. 7
    Spring Authorization Server

    RegisteredClient · AuthorizationService · JWKSource · Consent Pages · OIDC Discovery

  8. 8
    OAuth 2.0 Resource Server

    NimbusJwtDecoder · Authority Conversion · Opaque Tokens · Issuer Validation · Multi-Tenancy

  9. 9
    OpenID Connect (OIDC)

    ID Token Claims · UserInfo Endpoint · Standard Scopes · RP-Initiated Logout · Discovery Document

  10. 10
    Social Login — Google, GitHub, Microsoft

    oauth2-client Starter · CommonOAuth2Provider · OAuth2UserService · Account Linking · Onboarding Flow

  11. 11
    SAML 2.0 Authentication

    SP-Initiated Flow · RelyingPartyRegistration · Assertion Validation · Metadata Exchange · SAML vs OIDC

  12. 12
    LDAP & Active Directory Integration

    Distinguished Names · Bind Authentication · ActiveDirectoryLdapProvider · Group Search · LDAPS

  13. 13
    Role-Based Access Control (RBAC)

    Role Hierarchy · @PreAuthorize · @PostAuthorize · PermissionEvaluator · AuthorizationManager

  14. 14
    Attribute-Based Access Control (ABAC)

    PDP, PEP, PIP, PAP · Open Policy Agent · Rego Policies · SpEL Attribute Rules · RBAC vs ABAC

  15. 15
    Cryptography & Encryption in Spring

    AES-256-GCM · Hybrid Encryption · Spring Security Crypto · Column Encryption · Vault Transit

Web Security & OWASP Defence

10 topics · 10 published

  1. 16
    CSRF Protection

    CsrfFilter · Token Repositories · SameSite Cookies · Double Submit Cookie · When To Disable

  2. 17
    CORS Configuration

    Same-Origin Policy · Preflight Requests · CorsConfigurationSource · allowCredentials · Filter Ordering

  3. 18
    HTTP Security Headers

    HSTS · Content-Security-Policy · Nonce-Based CSP · X-Frame-Options · Permissions-Policy

  4. 19
    SSL/TLS & HTTPS in Spring Boot

    TLS Handshake · Keystores & PKCS12 · Mutual TLS · Cipher Suite Policy · HSTS Preload

  5. 20
    SQL Injection Prevention

    Attack Anatomy · Prepared Statements · JPQL Binding · Blind SQLi · sqlmap Testing

  6. 21
    XSS Prevention

    Reflected, Stored, DOM · Context-Aware Encoding · Thymeleaf Escaping · OWASP Java Encoder · HTML Sanitisers

  7. 22
    File Upload Security

    Extension Allowlists · Tika Content Detection · Path Traversal · ClamAV Scanning · Safe Storage & Serving

  8. 23
    SSRF Prevention

    Metadata Endpoints · IP Range Blocking · DNS Rebinding · Egress Controls · Webhook Validation

  9. 24
    Insecure Deserialisation

    Gadget Chains · ysoserial · ObjectInputFilter · Jackson Default Typing · Safe Formats

  10. 25
    OWASP Top 10 for LLM Applications

    Prompt Injection · Insecure Output Handling · Excessive Agency · Model DoS · Sensitive Disclosure

Advanced Authentication & Sessions

5 topics · 5 published

  1. 26
    Multi-Factor Authentication (MFA)

    TOTP RFC 6238 · Enrolment & QR Codes · Recovery Codes · Trusted Devices · WebAuthn & FIDO2

  2. 27
    Session Management & Security

    SessionCreationPolicy · Session Fixation · Concurrent Sessions · Cookie Flags · Spring Session + Redis

  3. 28
    Remember-Me Authentication

    Persistent Tokens · Series & Token Rotation · Theft Detection · Hash-Based Fallback · Validity Windows

  4. 29
    Single Sign-On (SSO)

    IdP Trust Model · SAML vs OIDC SSO · Silent Authentication · CAS Tickets · Keycloak

  5. 30
    Kerberos & SPNEGO

    KDC, TGT, Service Tickets · Keytab Files · SPNEGO Negotiate · SPN Registration · Browser Configuration

Security Testing & DevSecOps

5 topics · 5 published

  1. 31
    Testing Spring Security

    @WithMockUser · @WithUserDetails · MockMvc csrf() · Method Security Tests · Mock JWT

  2. 32
    Penetration Testing for Java Apps

    OWASP Testing Guide · User Enumeration · IDOR Hunting · JWT Attacks · Business Logic Flaws

  3. 33
    DevSecOps — Securing the Pipeline

    Secret Scanning · SAST & FindSecBugs · SCA & Dependency-Check · Container Scanning · DAST with ZAP

  4. 34
    Threat Modelling

    STRIDE · DREAD Scoring · Data Flow Diagrams · Trust Boundaries · PASTA

  5. 35
    Secrets Management & Key Security

    Secrets Inventory · Vault KV v2 · Dynamic Database Credentials · AppRole & K8s Auth · External Secrets Operator

Compliance & Advanced Architecture

5 topics · 5 published

  1. 36
    GDPR Compliance for Java Applications

    Data Subject Rights · Consent Records · Export APIs · Erasure & Anonymisation · Breach Notification

  2. 37
    Audit Logging & SIEM Integration

    What To Audit · Structured Event Format · Hash-Chained Immutability · Hibernate Envers · Splunk & ELK

  3. 38
    Zero-Trust Architecture

    NIST SP 800-207 · PE, PA, PEP · SPIFFE/SPIRE Identity · Micro-Segmentation · Just-in-Time Access

  4. 39
    Cryptographic Key Management

    Key Lifecycle · HSMs & PKCS#11 · Envelope Encryption · AWS KMS · Rotation & Rewrap

  5. 40
    SecureX — Zero-Trust Platform Architecture

    Auth Server · Security Gateway · OPA Policy Engine · Audit Service · Self-Service Portal

Build it for real

Reading a roadmap teaches you the vocabulary. Shipping the project is what makes it stick.

Other roadmaps