Securing Your Microservices with Spring Security, OAuth 2.0, and OpenID Connect (OIDC)
Spring Security provides the foundation for authentication and authorization in Spring applications. In a microservices architecture, however, identities, tokens, and access decisions must cross additional system boundaries. This course brings the core concepts of Spring Security together with OAuth 2.0, OpenID Connect (OIDC), and Spring Authorization Server.
Across two intensive training days, you will develop a deep understanding of the essential Spring Security concepts, one step at a time. You will secure an end-to-end sample application, starting with the security filter chain and continuing through an OAuth 2.0 resource server. Along the way, you will work directly with modern authentication and authorization mechanisms.
Practice drives the course. During hands-on sessions, you will configure, test, and observe the application’s security behavior. The exercises cover MFA, passkeys, secure password hashes, JWTs, opaque tokens, and both browser and service-to-service flows.
Agenda
Day 1: Spring Security Foundations and Practice
- Introduction to security
- Security objectives and threats, standards, authentication, authorization, and auditing
- Spring Security basics
- Core principles, the security filter chain, ‘SecurityContext’, and secure Spring Boot defaults
- Authentication
- Authentication building blocks, user stores, HTTP Basic, form login, MFA, passkeys, and session management
- Request and message authorization
- HTTP access rules, request matchers, roles, custom conditions, auditing, and WebSockets
- Method and domain-object security
- Security annotations, pre- and post-conditions, return values, and ‘SecurityContext’ propagation
- Security testing and observability
- Testing with MockMvc, test identities, security events, audit, and metrics
Day 2: Passwords, Web Security, and OAuth 2.0
- Secure password storage
- Adaptive hashes, ‘PasswordEncoder’, ‘DelegatingPasswordEncoder’, and transparent upgrades
- Protection against common web vulnerabilities
- Security headers, Content Security Policy, CSRF protection, HTTPS, and HSTS
- OAuth 2.0 and OpenID Connect (OIDC)
- Roles, grant types, PKCE, different token types, and social login
- Spring Authorization Server
- Endpoints, client registration, discovery, keys, and token customization
- Protecting and accessing resources with OAuth 2.0
- Resource server and client, JWTs, opaque tokens, service-to-service access, DPoP, and BFF
- Optional research exercises
- DPoP, passkey persistence, token trade-offs, and bonus exercises
- What’s next and final security review
- Staying current, diagnosing misconfigurations, and restoring protections
Your Benefits
In-depth knowledge of authentication, authorization, and modern security protocols
Practical experience with current Spring Security features
Hands-on labs with direct application to real projects
Practical tips, techniques, and best practices
Audience
Software developers, architects, and IT professionals who work with Spring or Java and want to deepen their knowledge of security.
Prerequisites
- Experience in developing Spring or Java applications
- Laptop with development environment (IntelliJ, Eclipse, VS Code)
- Maven & current Java version
- Internet access & permission to install software
Training Objectives
Understand the basic principles of Spring Security.
Implement authentication and authorization concepts.
Implement security configurations in Spring Boot.
Apply session management and CSRF protection.
Implement token-based authentication (e.g., JWT).
Integrate OAuth 2.0 and OpenID Connect into Spring Security.
Apply best practices for secure applications.
Your Trainers
Patrick Baumgartner
42talents
Java, Spring, Cloud
- Spring Boot Essentials
- Spring Modulith
- Spring Security in practice
Patrick Baumgartner is a Java Champion, passionate software crafter, and technical agile coach at 42talents. He supports teams in building elegant, robust solutions and specializes in cloud software with Java, the Spring ecosystem, and other open-source technologies.
As an active member of the Swiss communities for software craft, Java, and Agile, he regularly shares his knowledge. He values practical collaboration, experimentation, and continuous improvement—and prefers to learn together with others.
In-House Training
You can also book this training as an in-house training course exclusively for your team. Please use the enquiry form for more details.
Enquire nowRelevant Other Training Courses
Spring Boot Essentials
Gain a solid understanding of Spring Boot in four days—with practical examples for robust and modern applications.
by Request
Du möchtest die Grundlagen von Spring Boot erlernen und anwenden können? Dann schau dir dieses Training an.
from 2,025 €
iSAQB® Module WEBSEC
Du möchtest tiefer in die theoretischen Themen der Web-Security abtauchen? Dann ist dieses Training das Richtige für dich.
Spring AI
Create AI-based applications with Spring
by Request
Du möchtest dein Spring-Wissen im Hinblick auf AI weiter ausbauen? Dann sieh dir dieses Training an.