Main concepts of spring security with JWT tokens (Spring boot with REST controllers)

Viewed 1678

Introduction:
I have just started using spring boot. For understanding how it works I have tried to convert my existing project (spring MVC, JSP in frontend) to spring boot approach with REST-controller and AngularJS in frontend.

Facing problem:
During migration I have faced to big problem with security. As I understood the best way for having good security layer now is working with JWT tokens and supporting oauth2, on which there are a lot of posts/tutorials which give different information even about basics of the security layer architecture.

So the question is:
Could someone point out full list of security-layer parts/classes which are needed for having basic (but not hello world) security features for spring boot app with REST controllers. Please don't suggest to use stormpath: I want to implement it myself to get better understanding.

Reasoning of asking this big question here:
I have done my own investigation on this topic, but I thought that most of the links which I have checked contain a lot of bad practices, so possible incorrect architecture of security layer. so I really would like to know some kind of good practice of designing architecture of security layer.

Details on needed features:
I have standard list of features which I want to support.

  • oauth2 support (but also to have possibility to authenticate without it)
  • register request (creation of jwt token and returning to client)
  • login request (acquiring jwt token if user was registered)
  • logout request (releasing jwt token)
  • token timeout
  • multiple roles
  • business rest controllers which checks for authentication and authorization (could you please give an example portion of code)
  • business rest controllers which doesn't require security
  • basic filtering http urls (like excluding "statics" from allowed url addresses)

Current layers of the project:
Below are some additional information about my current project structure: Currently I have implemented the following modules:

  • controller: Currently MVC controllers, but I am going to convert them to REST
  • dto: Possibly will be changed a little bit, because of REST approach
  • model: Will stay unchanged after conversation
  • exception: For business logic
  • repository: Will stay unchanged after conversation
  • service: Possibly will be changed a little bit, because of micro-services
  • validator: Will stay unchanged after conversation
  • other business logic modules

If I understood correctly I will need to add two additional layers here:

  • configuration: I have already converted some xml configurators to java-configs, but haven't touched security configurators
  • security: I guest here will be placed authentication/authorization managers/tools. One of the goals of this question is to understand what exactly to place here.
  • app class with main method in the root package (relative root)
2 Answers
Related