Java Spring Boot की Security
In this page:
What is Spring Security?
Spring Security enterprise applications के लिए authentication (आप कौन हैं) और authorization (आप क्या करने की अनुमति रखते हैं) को handle करता है, और Spring Boot की request pipeline के साथ सीधे integrate होता है ताकि हर route के access rules controllers में बिखरने के बजाय केंद्रीय रूप से configured रहें।
उदाहरण: What is Spring Security?
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
public class Main {
public static void main(String[] args) {
// http.authorizeHttpRequests(auth -> auth.anyRequest().authenticated());
System.out.println("Authentication (who) + Authorization (what) centrally configured");
}
}
Login to try C/C++/Java/PHP code in the editor
Username and Password Authentication
Traditional username/password login schemes किसी user द्वारा submit की credentials की तुलना आपके database में store hashed values से करती हैं, account बनने के बाद plaintext password को कभी compare या store नहीं करते।
उदाहरण: Username and Password Authentication
public class Main {
public static void main(String[] args) {
String submittedPassword = "secret123";
String storedHash = "$2a$10$hashedvalue"; // never the plaintext password itself
System.out.println("Compare submitted credentials against " + storedHash);
}
}
Login to try C/C++/Java/PHP code in the editor
Role-Based Authorization
Role-based authorization आपको authenticated user को assigned roles (जैसे ADMIN या USER) के आधार पर specific methods या API URLs तक access सीमित करने देता है, ताकि एक ही application अलग codebases के बिना अलग तरह के users को अलग capabilities उजागर कर सके।
उदाहरण: Role-Based Authorization
import org.springframework.security.access.prepost.PreAuthorize;
public class Main {
@PreAuthorize("hasRole('ADMIN')") // restricts access based on the user's assigned role
void deleteUser(int id) {
System.out.println("Deleting user " + id);
}
public static void main(String[] args) {
new Main().deleteUser(5);
}
}
Login to try C/C++/Java/PHP code in the editor
Password Encoding
Passwords को database में लिखे जाने से पहले हमेशा hash किया जाना चाहिए, कभी plaintext में store नहीं। Spring specifically BCrypt जैसे encoders प्रदान करता है क्योंकि वे जान-बूझकर धीमे और salted हैं, जो चुराई गई password hashes को brute-force करना तेज़ general-purpose hash functions की तुलना में कहीं मुश्किल बना देता है।
उदाहरण: Password Encoding
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
public class Main {
public static void main(String[] args) {
BCryptPasswordEncoder encoder = new BCryptPasswordEncoder(); // deliberately slow and salted
String hashed = encoder.encode("myPassword");
System.out.println(hashed);
}
}
Login to try C/C++/Java/PHP code in the editor
JSON Web Token (JWT) Security
JSON Web Tokens (JWTs) self-contained, stateless tokens हैं जो incoming requests को authorize करने के लिए उपयोग होते हैं बिना server को session store रखने की ज़रूरत के, क्योंकि token खुद user के claims रखता है और हर request पर उसके signature से verify किया जाता है।
उदाहरण: JSON Web Token (JWT) Security
public class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJyaXlhIn0.signature"; // self-contained, no server-side session
System.out.println("Token carries claims and is verified by its signature: " + token);
}
}
Login to try C/C++/Java/PHP code in the editor
- कोई
PasswordEncoderbean define न करना, जिससे login करते समय 'There is no PasswordEncoder mapped for the id' errors आते हैं। hasRole("ROLE_ADMIN")का उपयोग करना, जबकिhasRole("ADMIN")पहले सेROLE_prefix जोड़ देता है (hasAuthorityexact text उपयोग करता है)।- source code में JWT signing secret को hard-code करना, जहां code रखने वाला कोई भी tokens forge कर सकता है; इसे configuration से load करें।
Chapter Quiz — Complete all 6 topics to unlock
0/6 topics done
Complete these topics first: