# Spring Boot Security

> Spring Security 6+ standards, Lambda DSL, and Hardening

- Skill: `majiayu000/spring-boot-security-4` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add majiayu000/spring-boot-security-4`
- Raw SKILL.md: https://api.skillmd.com/api/skills/majiayu000/spring-boot-security-4/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: majiayu000 (https://skillmd.com/u/majiayu000)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/majiayu000/spring-boot-security-4

---


# Spring Boot Security Standards

## **Priority: P0 (CRITICAL)**

## Implementation Guidelines

### Configuration (Spring Security 6+)

- **Lambda DSL**: ALWAYS use Lambda DSL.
- **SecurityFilterChain**: Expose as `@Bean`. Do not extend `WebSecurityConfigurerAdapter`.
- **Statelessness**: Enforce `SessionCreationPolicy.STATELESS` for REST APIs.

#### Golden Snippet

See [Security Configuration](references/implementation.md) for full `SecurityFilterChain` example.

### Authentication vs Authorization

- **Authentication**: Validation of credentials (Who are you?). Use `AuthenticationManager` or `JwtDecoder`.
- **Authorization**: Verification of access rights (Can you do this?). Use `@PreAuthorize`.

### JWT Best Practices

- **Algorithm**: Enforce `RS256` or `HS256`. **Reject `none` algorithm**.
- **Claims**: Validate `iss`, `aud`, and `exp`.
- **Tokens**: Short-lived access tokens (15m), secure refresh tokens (httpOnly cookie).

### Hardening Checklist

- [ ] **CSRF**: Disabled for pure APIs? Enabled + Cookie for Browser Apps?
- [ ] **CORS**: Specific origins permitted? No `*` with credentials?
- [ ] **Headers**: HSTS, Content-Type-Options, X-Frame-Options enabled?
- [ ] **Secrets**: No hardcoded keys? Loaded from Vault/Env?
- [ ] **Rate Limiting**: Applied on login/expensive endpoints?
- [ ] **Dependencies**: Scanned for CVEs?

## Anti-Patterns

- **Adapter Extension**: `**No Adapter**: Use SecurityFilterChain bean.`
- **Chained Calls**: `**No .and()**: Use Lambda DSL.`
- **Hardcoded Secrets**: `**No Secrets**: Use Vault/Env.`
- **Legacy Matchers**: `**No antMatchers**: Use requestMatchers.`

## References

- [Implementation Examples](references/implementation.md)

## Related Topics

common/security-standards | architecture

