Spring Security
The whole framework: the servlet filter chain, authentication and authorization, method security, OAuth2 and OIDC, CSRF, CORS and session protection, and the reactive variant. Security questions are where interviewers most reliably find gaps between configuration copied and configuration understood.
part ofSpring Frameworkoverview, primer and where to startread it →on this pageshowhide
explore
- Filter Chain Architecture30 questions
- DelegatingFilterProxy5 questions
- FilterChainProxy & SecurityFilterChain5 questions
- SecurityFilterChain Bean & Lambda DSL5 questions
- Security Filter Ordering5 questions
- SecurityContextHolder & Propagation5 questions
- ExceptionTranslationFilter & EntryPoint5 questions
- Authentication35 questions
- AuthenticationManager & ProviderManager5 questions
- PasswordEncoder & DelegatingPasswordEncoder5 questions
- Form Login & HTTP Basic5 questions
- Anonymous Authentication5 questions
- Authentication Events5 questions
- Logout Handling5 questions
- HTTP Authorization18 questions
- Method Security24 questions
- @EnableMethodSecurity5 questions
- @PreAuthorize / @PostAuthorize5 questions
- @Secured & @RolesAllowed5 questions
- @PreFilter / @PostFilter5 questions
- PermissionEvaluator & ACLs4 questions
- OAuth2, OIDC & Resource Server30 questions
- OAuth2 / OIDC Login5 questions
- OAuth2 Client & Authorized Clients5 questions
- Resource Server: JWT5 questions
- JWT Validators & Encoder5 questions
- Resource Server: Opaque Tokens5 questions
- Spring Authorization Server5 questions
- Web Exploit & Session Protections30 questions
- CSRF Protection5 questions
- CORS Integration5 questions
- Session Management & Fixation5 questions
- Concurrent Session Control5 questions
- Remember-Me5 questions
- Security HTTP Headers5 questions
- Reactive Security & Testing19 questions
- WebFlux Security Chain5 questions
- ReactiveSecurityContextHolder5 questions
- Test Annotations: @WithMockUser5 questions
- SecurityMockMvc & WebTestClient Mutators4 questions
questions
186 · 7 sectionsWhat is DelegatingFilterProxy and why does Spring Security need it?
basics
~20 sDelegatingFilterProxy is a servlet Filter registered with the container that forwards requests to a Spring-managed filter bean (the security filter chain). It lets Spring beans act as filters even though the container created the proxy.
What is the ExceptionTranslationFilter and what job does it do in the Spring Security filter chain?
basics
~20 sIt's a filter that catches two security exceptions thrown further down the chain — AuthenticationException (not logged in) and AccessDeniedException (logged in but not allowed) — and turns them into an HTTP response instead of an error page.
What is FilterChainProxy in Spring Security, and what is its job?
basics
~10 sFilterChainProxy is the single servlet filter Spring Security registers. For each request it picks the first matching SecurityFilterChain and runs that chain's security filters in order.
What is the Spring Security filter chain, and why does the ORDER of filters in it matter?
basics
~20 sSpring Security is a chain of servlet filters run in a fixed order. Each filter does one job (load context, check CSRF, authenticate, authorize). Order matters because later filters depend on what earlier ones set up — e.g. you must load the user before checking permissions.
What is a SecurityFilterChain @Bean and how do you declare one in modern Spring Security?
basics
~10 sYou write a method annotated with @Bean that takes an HttpSecurity object, configures the rules on it, and returns http.build(), which produces a SecurityFilterChain. Spring registers it to secure your HTTP requests.
What does formLogin() enable in Spring Security, and what is the role of UsernamePasswordAuthenticationFilter?
basics
~10 sformLogin() turns on a browser login form. Spring adds UsernamePasswordAuthenticationFilter, which intercepts the POST to /login, reads the username and password fields, and asks the AuthenticationManager to verify them.
What does Spring Security's logout() DSL configure, and what happens when a user hits /logout?
basics
~10 sThe logout() DSL wires up a LogoutFilter. When a user POSTs to /logout, the filter clears the logged-in user from the SecurityContext, invalidates the HTTP session, and redirects to a success page (default /login?logout).
What is the contract of AuthenticationManager.authenticate()? What are its three possible outcomes?
basics
~10 sAuthenticationManager has one method, authenticate(Authentication). It returns a fully authenticated Authentication if credentials are valid, throws an AuthenticationException if they are invalid, or returns null if it cannot decide.
What is Spring Security's PasswordEncoder and why should you use it instead of storing passwords directly?
basics
~20 sPasswordEncoder is an interface that turns a raw password into a one-way, salted hash. You store the hash, never the plaintext, so a database leak doesn't expose real passwords. Its matches() method verifies a login attempt.
What is UserDetailsService in Spring Security, and what does loadUserByUsername return?
basics
~20 sUserDetailsService is an interface with one method, loadUserByUsername(String), that looks up a user by name and returns a UserDetails object holding the username, encoded password, and authorities (roles). It throws UsernameNotFoundException if no user exists.
What does @EnableMethodSecurity do, and what are its prePostEnabled, securedEnabled, and jsr250Enabled flags?
basics
~10 s@EnableMethodSecurity turns on security checks on individual methods (not just URLs). prePostEnabled activates @PreAuthorize/@PostAuthorize (on by default), securedEnabled activates @Secured, and jsr250Enabled activates @RolesAllowed. You put it on a @Configuration class.
What do @PreAuthorize and @PostAuthorize do, and how do you turn them on in a Spring application?
basics
~10 s@PreAuthorize checks a rule before a method runs; @PostAuthorize checks after it returns. You enable them by adding @EnableMethodSecurity to a configuration class. If the rule is false, access is denied with an exception.
What are @Secured and @RolesAllowed in Spring Security, and what do they do?
basics
~10 sBoth are method-level annotations that restrict who can call a method based on their roles. @RolesAllowed is a Java standard (JSR-250); @Secured is Spring's own. You list allowed roles and Spring blocks everyone else.
How do you implement and register a custom PermissionEvaluator in Spring Security 6?
basics
~10 sImplement the PermissionEvaluator interface (its two hasPermission methods) with your own logic, then publish a MethodSecurityExpressionHandler bean, calling setPermissionEvaluator() so @PreAuthorize's hasPermission() uses it.
What variables can you reference in @PreAuthorize/@PostAuthorize SpEL — how do you read method arguments, the principal, and the return value?
basics
~20 sYou can reference method arguments by name (or #p0, #p1), the current user via authentication and principal, and — only in @PostAuthorize — the method's result via returnObject. You combine them with helpers like hasRole() and hasAuthority().
What is Spring Authorization Server, and what role do RegisteredClient and RegisteredClientRepository play in it?
basics
~20 sSpring Authorization Server is a standalone project that turns your app into an OAuth2/OIDC provider — it issues tokens. A RegisteredClient is one app allowed to request tokens; RegisteredClientRepository stores and looks up those clients.
What does JwtTimestampValidator check on an incoming JWT, and why does it allow a small clock skew by default?
basics
~20 sJwtTimestampValidator checks the token's time claims: it rejects tokens that are expired (exp) or not yet valid (nbf). It allows a default 60-second clock skew so tokens are not rejected just because server clocks differ slightly.
What is an OAuth2AuthorizedClient in Spring Security, and how does oauth2Client() differ from oauth2Login()?
basics
~20 sAn OAuth2AuthorizedClient holds the access token (and optional refresh token) your app got to call another API on a user's behalf. oauth2Client() lets your app CALL other APIs; oauth2Login() logs the USER into your app.
What does oauth2Login() enable in a Spring Security application, and what OAuth2 flow does it use?
basics
~20 soauth2Login() lets users sign in to your app using an external provider like Google or GitHub. It uses the OAuth2 authorization-code flow: Spring redirects the user to the provider, gets a code back, and exchanges it for tokens to log the user in.
How do you configure a Spring Security application to act as an OAuth2 Resource Server that accepts JWT bearer tokens?
basics
~10 sIn the SecurityFilterChain, call http.oauth2ResourceServer(oauth2 -> oauth2.jwt(...)). Add a jwk-set-uri or issuer-uri in application.yml so Spring can fetch the keys and verify each incoming Bearer token's signature.
What is CORS, and how do you enable it in a Spring Security application?
basics
~20 sCORS lets a browser page from one origin call an API on another origin. In Spring Security you turn it on with http.cors() in the SecurityFilterChain and provide a CorsConfigurationSource bean that lists allowed origins, methods, and headers.
What is CSRF, and how does Spring Security protect against it by default?
basics
~10 sCSRF tricks a logged-in user's browser into sending an unwanted state-changing request using their cookies. Spring Security defends with a secret token (CsrfFilter) that must accompany every POST/PUT/DELETE/PATCH, which an attacker's site cannot know.
Which HTTP security response headers does Spring Security add by default, and where does that behavior come from?
basics
~10 sBy default Spring Security adds protective response headers automatically: Cache-Control (no-store), X-Content-Type-Options: nosniff, X-Frame-Options: DENY, and Strict-Transport-Security (HSTS) on HTTPS requests. You don't configure anything to get them.
What is session fixation and how does Spring Security protect against it by default?
basics
~20 sSession fixation is when an attacker forces a victim to use a known session ID, then hijacks it after login. Spring Security defends by changing the session ID at login (changeSessionId), so the old ID is useless.
What is the difference between maxSessionsPreventsLogin(true) and (false)?
basics
~20 sWith false (default) a new login is allowed and the oldest session is expired. With true the new login is refused (throws SessionAuthenticationException) and existing sessions stay alive — old sessions win over new ones.
In a Spring MockMvc test, how do you make a request run as an authenticated user, and why does a POST often need `.with(csrf())`?
basics
~10 sUse SecurityMockMvcRequestPostProcessors: mockMvc.perform(get("/").with(user("alice").roles("ADMIN"))) runs the request as that user. State-changing requests (POST/PUT/DELETE) need .with(csrf()) because CSRF protection rejects them without a valid token.
What is ReactiveSecurityContextHolder and how does it differ from the classic SecurityContextHolder?
basics
~10 sIn WebFlux, ReactiveSecurityContextHolder stores the logged-in user's SecurityContext inside the Reactor Context (attached to the request's reactive stream) instead of a ThreadLocal, so it survives even when work hops between threads.
What does @EnableWebFluxSecurity do, and how do you define a security configuration in a Spring WebFlux application?
basics
~10 s@EnableWebFluxSecurity turns on Spring Security for a reactive WebFlux app. You then declare a @Bean of type SecurityWebFilterChain that configures which URLs are protected and how users log in.
What does @WithMockUser do in a Spring Security test, and what are its defaults?
basics
~10 s@WithMockUser runs a test as if a logged-in user made the request, without hitting a real login. By default the user is named 'user' with password 'password' and the role USER.
How do you obtain the authenticated user inside a WebFlux controller or service?
basics
~10 sEither inject the user as a method parameter (@AuthenticationPrincipal MyUser user, or a Mono<Authentication>/Principal argument), or in a service compose ReactiveSecurityContextHolder.getContext().map(SecurityContext::getAuthentication).