Hard20 minSpring Boot Fundamentals
UpdatedAug 5, 2026
Edit

Spring Boot Security

Question Variations

  • "How do you configure authorization in modern Spring Security?"
  • "When is CSRF protection relevant?"
  • "Why combine route and method security?"

Why This Is Asked

Security configuration requires an explicit request policy and distinguishes authentication from authorization.

Key Concepts

  • A SecurityFilterChain defines HTTP security behavior.
  • Authentication establishes identity; authorization evaluates permissions.
  • CSRF, sessions, CORS, and bearer tokens have distinct threat models.
  • Method security complements route-level rules for sensitive operations.

Question Variations

  • “How do you configure authorization in modern Spring Security?”
  • “When is CSRF protection relevant?”
  • “Why combine route and method security?”

Answers by Technology

+ Add Variant
Spring BootImprove this answer ✏️

Expected Answer (Spring Boot 4.1.0 / Java 17+)

Configure security with a SecurityFilterChain that states which routes are public and which require authentication. Authentication establishes the caller identity; authorization checks whether that identity may take the action. Choose session, bearer-token, and CSRF controls based on the client and threat model rather than disabling defaults broadly. Add method-level checks for sensitive service operations that could be reached through multiple paths.

Why It Matters

An explicit filter policy prevents accidental public endpoints and makes authorization reviewable.

Code Example

@Bean
SecurityFilterChain security(HttpSecurity http) throws Exception {
  return http.authorizeHttpRequests(auth -> auth
      .requestMatchers("/actuator/health").permitAll()
      .anyRequest().authenticated())
    .httpBasic(Customizer.withDefaults()).build();
}

Common Mistakes

  • Disabling CSRF without understanding browser sessions: Cookie-authenticated state changes can become vulnerable.
  • Using only URL rules for sensitive actions: Alternate entry points can miss required policy.

Follow-up Questions

  • When is CSRF relevant? (Answer: Usually for browser clients using automatically sent credentials such as cookies.)
  • What does authenticated() guarantee? (Answer: Identity is established, not necessarily resource-level permission.)