← Back to Advanced Java Course | Chapter 10: Spring Boot | Lesson 4 of 6

Java Spring Boot की Security

Spring Security आपके application की रक्षा यह जांचकर करता है कि लोग कौन हैं और वे क्या कर सकते हैं, जैसे किसी club का bouncer। यह logins, roles और passwords को handle करता है।

What is Spring Security?

Spring Security enterprise applications के लिए authentication (आप कौन हैं) और authorization (आप क्या करने की अनुमति रखते हैं) को handle करता है, और Spring Boot की request pipeline के साथ सीधे integrate होता है ताकि हर route के access rules controllers में बिखरने के बजाय केंद्रीय रूप से configured रहें।

उदाहरण: What is Spring Security?

java
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
public class Main {
	public static void main(String[] args) {
		// http.authorizeHttpRequests(auth -> auth.anyRequest().authenticated());
		System.out.println("Authentication (who) + Authorization (what) centrally configured");
	}
}

Username and Password Authentication

Traditional username/password login schemes किसी user द्वारा submit की credentials की तुलना आपके database में store hashed values से करती हैं, account बनने के बाद plaintext password को कभी compare या store नहीं करते।

उदाहरण: Username and Password Authentication

java
public class Main {
	public static void main(String[] args) {
		String submittedPassword = "secret123";
		String storedHash = "$2a$10$hashedvalue"; // never the plaintext password itself
		System.out.println("Compare submitted credentials against " + storedHash);
	}
}

Role-Based Authorization

Role-based authorization आपको authenticated user को assigned roles (जैसे ADMIN या USER) के आधार पर specific methods या API URLs तक access सीमित करने देता है, ताकि एक ही application अलग codebases के बिना अलग तरह के users को अलग capabilities उजागर कर सके।

उदाहरण: Role-Based Authorization

java
import org.springframework.security.access.prepost.PreAuthorize;
public class Main {
	@PreAuthorize("hasRole('ADMIN')") // restricts access based on the user's assigned role
	void deleteUser(int id) {
		System.out.println("Deleting user " + id);
	}
	public static void main(String[] args) {
		new Main().deleteUser(5);
	}
}

Password Encoding

Passwords को database में लिखे जाने से पहले हमेशा hash किया जाना चाहिए, कभी plaintext में store नहीं। Spring specifically BCrypt जैसे encoders प्रदान करता है क्योंकि वे जान-बूझकर धीमे और salted हैं, जो चुराई गई password hashes को brute-force करना तेज़ general-purpose hash functions की तुलना में कहीं मुश्किल बना देता है।

उदाहरण: Password Encoding

java
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
public class Main {
	public static void main(String[] args) {
		BCryptPasswordEncoder encoder = new BCryptPasswordEncoder(); // deliberately slow and salted
		String hashed = encoder.encode("myPassword");
		System.out.println(hashed);
	}
}

JSON Web Token (JWT) Security

JSON Web Tokens (JWTs) self-contained, stateless tokens हैं जो incoming requests को authorize करने के लिए उपयोग होते हैं बिना server को session store रखने की ज़रूरत के, क्योंकि token खुद user के claims रखता है और हर request पर उसके signature से verify किया जाता है।

उदाहरण: JSON Web Token (JWT) Security

java
public class Main {
	public static void main(String[] args) {
		String token = "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJyaXlhIn0.signature"; // self-contained, no server-side session
		System.out.println("Token carries claims and is verified by its signature: " + token);
	}
}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. कोई PasswordEncoder bean define न करना, जिससे login करते समय 'There is no PasswordEncoder mapped for the id' errors आते हैं।
  2. hasRole("ROLE_ADMIN") का उपयोग करना, जबकि hasRole("ADMIN") पहले से ROLE_ prefix जोड़ देता है (hasAuthority exact text उपयोग करता है)।
  3. source code में JWT signing secret को hard-code करना, जहां code रखने वाला कोई भी tokens forge कर सकता है; इसे configuration से load करें।
🔒

Chapter Quiz — Complete all 6 topics to unlock

0/6 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.