Learning paths

Spring Core and Spring Security in depth

The IoC container, dependency injection, scopes, configuration, proxies and events; then the security filter chain, authentication, password storage, authorization, JWT, OAuth 2.0 and CSRF/CORS. Every step has a lab or diagram.

  • For: You use Spring Boot and want to understand what the framework is doing for you, and secure an API properly.
  • By the end: You can explain how Spring wires and proxies your beans, debug the classic traps, and design authentication and authorization for a real API.
  • Size: 15 lessons (45 min of reading, plus time to try the code), intermediate to advanced
  1. Bean scopes and lifecycleSpring Core and Spring MVC, intermediate, 3 min
  2. Aspect-oriented programmingSpring Core and Spring MVC, advanced, 3 min
  3. Application events: decoupling with @EventListenerSpring Core and Spring MVC, intermediate, 3 min
  4. Spring Security: the big pictureSpring Security, advanced, 3 min
  5. Storing passwords: hashing, salting and BCryptSpring Security, beginner, 3 min
  6. CSRF, CORS and security headersSpring Security, intermediate, 3 min

Other paths