home.social

#springsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #springsecurity, aggregated by home.social.

fetched live
  1. [Перевод] Axelix выходит в общий доступ. Путь в тысячу миль начинается с первого шага

    От имени основной команды Axelix и всех, кто внёс вклад в сообщество, я хочу заявить: мы наконец это сделали. Axelix, наконец, выходит в GA (Generally Available — общедоступная версия)! Для тех, кто не знает - Axelix это продукт с открытым (Open Source) ядром, который позволяет выявлять распространённые проблемы, подводные камни и неэффективности в Java-приложениях. Ядро продукта лежит на GitHub - можете использовать, это бесплатно. В этом посте я хочу поделиться историей и мотивацией, стоящей за продуктом в целом. Надеюсь, вам будет интересно.

    habr.com/ru/companies/spring_a

    #java #springboot #springdata #springcloud #springsecurity #opensource

  2. CVE-2026-22752: CRITICAL auth bypass in Spring Authorization Server (CVSS 9.6). Low-priv attackers can fully compromise confidentiality & integrity. No patch or workaround — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622752 #infosec

  3. 🔒 HIGH severity: Spring for GraphQL (v1.0.0 – 2.0.3) is affected by CVE-2026-41856 — improper access control can bypass security annotations, risking unauthorized access. Review your authorization logic ASAP. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #GraphQL

  4. SAP Patches Critical Flaws in Commerce Cloud and S/4HANA

    SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.

    osintsights.com/sap-patches-cr

    #SapCommerceCloud #Cve202634263 #CodeInjection #ServersideCodeExecution #SpringSecurity

  5. Check out what's new in the #Spring community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka

  6. Check out what's new in the community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

  7. 🚨 CVE-2026-22732 (CRITICAL, CVSS 9.1): Spring Security 5.7.0 – 7.0.3 vulnerability lets HTTP headers go unwritten, risking CSP/HSTS bypass. No auth needed, remote exploit possible. Upgrade urgently & enforce headers via WAF/CDN! radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622732

  8. Check out what's new in the #Spring community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka

  9. Check out what's new in the community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

  10. Ever wondered if you're handling passwords securely in Java? 🤔 I switched to char[] instead of String — it’s mutable, log-safe, and I can wipe it from memory after use. But here's the kicker: Spring Security still expects String in many places. 🔄

    Is it worth using char[] despite the framework limits? What’s your go-to strategy for securing passwords in memory?

    Full breakdown on my blog: manueltechlabs.com/posts/why-i
    #Java #SpringSecurity #Cybersecurity #DevCommunity

  11. This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.

    👉 Read it here: bit.ly/3DWoKFX

    #Java #Spring #InfoQ

  12. This article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow .

    👉 Read it here: bit.ly/3DWoKFX

  13. 🔍 Explore the best of #Java in 2025!

    We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪

    #SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering

  14. 🔍 Explore the best of in 2025!

    We’ve handpicked our favorite articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always of the curve! Knowledge is power! 💪

  15. There is also #SpringSecurity integration and #Actuator integration examples on the website. Really interested to hear feedback from #Spring developers.

  16. There is also integration and integration examples on the website. Really interested to hear feedback from developers.

  17. Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.

    Mehr von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    @xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity

  18. Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.

    Mehr von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    @xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity

  19. Dive into the latest releases from #Spring 👉 bit.ly/3K9wRmf

    GA releases of Spring Boot, Spring Security, Spring for GraphQL, Spring Integration, Spring Modulith, Spring REST Docs and Spring Batch.

    #Java #SpringBoot #SpringSecurity #SpringFramework #ApacheKafka #AMQP #GraphQL

  20. Dive into the latest releases from 👉 bit.ly/3K9wRmf

    GA releases of Spring Boot, Spring Security, Spring for GraphQL, Spring Integration, Spring Modulith, Spring REST Docs and Spring Batch.

  21. You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.

    Learn what #XDEV SSE solves: javapro.io/2025/07/25/explorin

    @xdevsoftware #OpenSource #Vaadin

  22. You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.

    Learn what #XDEV SSE solves: javapro.io/2025/07/25/explorin

    @xdevsoftware #OpenSource #Vaadin

  23. 🍃 The next installment of the Road to GA series about a cross-project, collaborative effort on new capabilities for HTTP service clients in #Spring is now live!

    spring.io/blog/2025/09/23/http

    #SpringFramework #SpringBoot #SpringCloud #SpringSecurity

  24. 🍃 The next installment of the Road to GA series about a cross-project, collaborative effort on new capabilities for HTTP service clients in #Spring is now live!

    spring.io/blog/2025/09/23/http

    #SpringFramework #SpringBoot #SpringCloud #SpringSecurity

  25. Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    #OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity

  26. Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    #OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity

  27. Spring Security для начинающих: конспект от аутентификации до JWT

    На Хабре уже много статей про Spring Security — от кратких заметок до глубоких разборов. В этой статье я решил собрать всё в формате конспект-мануала, который можно читать как пошаговое введение: от базовой аутентификации и фильтров до JWT и OAuth2. Это материал, собранный по официальной документации и дополненный разъяснениями «на простом языке». Я не работал в больших enterprise-командах, поэтому буду рад комментариям и советам от более опытных коллег. Местами я использовал помощь ChatGPT: он помог структурировать материал и сделать стиль более читабельным, ближе к документации.

    habr.com/ru/articles/946912/

    #java #spring_security #springsecurity

  28. #SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.

    A must-read for security-conscious teams: javapro.io/2025/07/25/explorin

    @xdevsoftware @vaadin #Vaadin #OAuth2

  29. #SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.

    A must-read for security-conscious teams: javapro.io/2025/07/25/explorin

    @xdevsoftware @vaadin #Vaadin #OAuth2

  30. Check out what's new in the #Spring community 👉 bit.ly/3JyVeZX

    The second milestone releases of Spring Boot, Spring Security, Spring Authorization Server, Spring for GraphQL, Spring Session, Spring Integration, Spring REST Docs, Spring Batch and Spring for Apache Pulsar.

    #Java #SpringBoot #SpringSecurity SpringFramework #SpringBatch

  31. Check out what's new in the community 👉 bit.ly/3JyVeZX

    The second milestone releases of Spring Boot, Spring Security, Spring Authorization Server, Spring for GraphQL, Spring Session, Spring Integration, Spring REST Docs, Spring Batch and Spring for Apache Pulsar.

    SpringFramework

  32. #SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: javapro.io/de/xdev-sse-verbess

    #OpenSource #Vaadin @vaadin

  33. #SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: javapro.io/de/xdev-sse-verbess

    #OpenSource #Vaadin @vaadin

  34. Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.

    Code & Docs: javapro.io/de/xdev-sse-verbess

    #OAuth2 @vaadin

  35. Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.

    Code & Docs: javapro.io/de/xdev-sse-verbess

    #OAuth2 @vaadin

  36. Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.

    Read it if #SpringSecurity alone isn’t enough: javapro.io/2025/07/25/explorin
    @xdevsoftware #Vaadin

  37. Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.

    Read it if #SpringSecurity alone isn’t enough: javapro.io/2025/07/25/explorin
    @xdevsoftware #Vaadin

  38. Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!

    Read #JAVAPRO: javapro.io/2025/07/25/explorin

    @xdevsoftware

  39. Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!

    Read #JAVAPRO: javapro.io/2025/07/25/explorin

    @xdevsoftware

  40. @xdevsoftware

    🔐 We built it because we needed it – now it’s yours!

    We often ran into the same challenge: handling OAuth2/OIDC securely and cleanly with .

    So we created XDEV SSE – a practical extension born out of real-world needs. It simplifies authentication flows, boosts security, and integrates seamlessly with Vaadin.

  41. @xdevsoftware

    🔐 We built it because we needed it – now it’s yours!

    We often ran into the same challenge: handling OAuth2/OIDC securely and cleanly with #SpringSecurity.

    So we created XDEV SSE – a practical extension born out of real-world needs. It simplifies authentication flows, boosts security, and integrates seamlessly with Vaadin.

  42. Check out our latest blog post on XDEV SSE! 🔐 Learn how our extension for #SpringSecurity simplifies OAuth2/OIDC handling, improves security, and integrates seamlessly with #Vaadin.

    Dive into the code & discover its features: xdev.software/news

    #Java #OpenSource

  43. Check out our latest blog post on XDEV SSE! 🔐 Learn how our extension for #SpringSecurity simplifies OAuth2/OIDC handling, improves security, and integrates seamlessly with #Vaadin.

    Dive into the code & discover its features: xdev.software/news

    #Java #OpenSource

  44. Dive into the latest releases from #Spring 👉 bit.ly/44v29Lx

    The first milestone release of Spring Vault 4.0; and point releases of Spring Boot, Spring Security, Spring Authorization Server, Spring Session, Spring Integration, Spring Modulith, Spring REST Docs, Spring AMQP, Spring for Apache Kafka, Spring for Apache Pulsar and Spring Web Services.

    #Java #SpringBoot #SpringSecurity #SpringModulith #SpringVault

  45. Dive into the latest releases from #Spring 👉 bit.ly/3STMS0b

    GA releases of Spring Boot, Spring Security, Spring Authorization Server, Spring Session, Spring Integration, Spring for GraphQL, Spring AI and Spring Web Services.

    #Java #SpringBoot #SpringSecurity #SpringAI

  46. Dive into the latest releases from #Spring 👉 bit.ly/3EJAUTq

    First release candidates of Spring Boot, Spring Data 2025.0.0, Spring Security, Spring Authorization Server, Spring Session, Spring Integration, Spring Modulith & Spring Web Services.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringModulith #SpringVault #SpringFramework

  47. This #InfoQ article provides a detailed solution for registering & authenticating a user through a client-side #JavaScript application using the #SpringSecurity infrastructure, access & refresh tokens.

    We explore the process in detail with helpful flow diagrams!

    🔗 Get a deeper understanding: bit.ly/3DWoKFX

    #Java #Spring

  48. Dive into the latest releases from #Spring 👉 bit.ly/3Y32ilE

    Spring Boot, Spring Security, Spring Authorization Server, Spring for GraphQL, Spring Integration, Spring AMQP, Spring for Apache Kafka and Spring Web Services.

    #Java #SpringBoot #SpringFramework #SpringSecurity #SpringBatch #SpringModulith

  49. Dive into the latest releases from #Spring 👉 bit.ly/3QuNKaD

    Releases of: Spring Boot, Spring Security, Spring Authorization Server, Spring Integration, Spring AI and Spring AMQP.

    Many of these releases are included in Spring Boot 3.5.0-M2, 3.4.3 & 3.3.9.

    #Java #SpringData #SpringCloud #SpringBoot #SpringFramework #SpringSecurity