#springsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #springsecurity, aggregated by home.social.
-
[Перевод] Axelix выходит в общий доступ. Путь в тысячу миль начинается с первого шага
От имени основной команды Axelix и всех, кто внёс вклад в сообщество, я хочу заявить: мы наконец это сделали. Axelix, наконец, выходит в GA (Generally Available — общедоступная версия)! Для тех, кто не знает - Axelix это продукт с открытым (Open Source) ядром, который позволяет выявлять распространённые проблемы, подводные камни и неэффективности в Java-приложениях. Ядро продукта лежит на GitHub - можете использовать, это бесплатно. В этом посте я хочу поделиться историей и мотивацией, стоящей за продуктом в целом. Надеюсь, вам будет интересно.
https://habr.com/ru/companies/spring_aio/articles/1065202/
#java #springboot #springdata #springcloud #springsecurity #opensource
-
CVE-2026-22752: CRITICAL auth bypass in Spring Authorization Server (CVSS 9.6). Low-priv attackers can fully compromise confidentiality & integrity. No patch or workaround — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-22752-vulnerability-in-spring-security-sp-73162920d784b7e4 #OffSeq #SpringSecurity #CVE202622752 #infosec
-
🔒 HIGH severity: Spring for GraphQL (v1.0.0 – 2.0.3) is affected by CVE-2026-41856 — improper access control can bypass security annotations, risking unauthorized access. Review your authorization logic ASAP. https://radar.offseq.com/threat/cve-2026-41856-cwe-284-improper-access-control-in--4879e7fe #OffSeq #SpringSecurity #GraphQL
-
SAP Patches Critical Flaws in Commerce Cloud and S/4HANA
SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.
#SapCommerceCloud #Cve202634263 #CodeInjection #ServersideCodeExecution #SpringSecurity
-
Check out what's new in the #Spring community 👉 https://bit.ly/3NMwcbY
The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.
#Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka
-
Check out what's new in the #Spring community 👉 https://bit.ly/3NMwcbY
The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.
#Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka
-
🚨 CVE-2026-22732 (CRITICAL, CVSS 9.1): Spring Security 5.7.0 – 7.0.3 vulnerability lets HTTP headers go unwritten, risking CSP/HSTS bypass. No auth needed, remote exploit possible. Upgrade urgently & enforce headers via WAF/CDN! https://radar.offseq.com/threat/cve-2026-22732-vulnerability-in-spring-spring-secu-2c8fbdd8 #OffSeq #SpringSecurity #CVE202622732
-
EdDSA (Ed25519) JWT verification on Spring Boot 4 resource servers — the missing pieces I had to stitch together.
#Spring #SpringSecurity #SpringBoot #SpringBoot4 #Java #EdDSA #Ed25519 #Security
Enjoy tracker free reading with us. #privacy #privacymatters
-
EdDSA (Ed25519) JWT verification on Spring Boot 4 resource servers — the missing pieces I had to stitch together.
#Spring #SpringSecurity #SpringBoot #SpringBoot4 #Java #EdDSA #Ed25519 #Security
Enjoy tracker free reading with us. #privacy #privacymatters
-
EdDSA (Ed25519) JWT verification on Spring Boot 4 resource servers — the missing pieces I had to stitch together.
#Spring #SpringSecurity #SpringBoot #SpringBoot4 #Java #EdDSA #Ed25519 #Security
Enjoy tracker free reading with us. #privacy #privacymatters
-
EdDSA (Ed25519) JWT verification on Spring Boot 4 resource servers — the missing pieces I had to stitch together.
#Spring #SpringSecurity #SpringBoot #SpringBoot4 #Java #EdDSA #Ed25519 #Security
Enjoy tracker free reading with us. #privacy #privacymatters
-
Check out what's new in the #Spring community 👉 https://bit.ly/4kZSJyw
The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.
#Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka
-
Check out what's new in the #Spring community 👉 https://bit.ly/4kZSJyw
The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.
#Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka
-
Ever wondered if you're handling passwords securely in Java? 🤔 I switched to char[] instead of String — it’s mutable, log-safe, and I can wipe it from memory after use. But here's the kicker: Spring Security still expects String in many places. 🔄
Is it worth using char[] despite the framework limits? What’s your go-to strategy for securing passwords in memory?
Full breakdown on my blog: https://manueltechlabs.com/posts/why-i-used-char%5B%5D-for-passwords-in-spring-security-and-what-i-learned/
#Java #SpringSecurity #Cybersecurity #DevCommunity -
This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.
🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.
👉 Read it here: https://bit.ly/3DWoKFX
-
This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.
🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.
👉 Read it here: https://bit.ly/3DWoKFX
-
🔍 Explore the best of #Java in 2025!
We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:
➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
https://bit.ly/47KRUUX➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
https://bit.ly/3DWoKFX➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
https://bit.ly/4oNmLqH➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
https://bit.ly/4lTYBc3➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
https://bit.ly/46Pj4tXStay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪
#SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering
-
🔍 Explore the best of #Java in 2025!
We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:
➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
https://bit.ly/47KRUUX➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
https://bit.ly/3DWoKFX➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
https://bit.ly/4oNmLqH➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
https://bit.ly/4lTYBc3➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
https://bit.ly/46Pj4tXStay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪
#SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering
-
There is also #SpringSecurity integration and #Actuator integration examples on the website. Really interested to hear feedback from #Spring developers.
-
There is also #SpringSecurity integration and #Actuator integration examples on the website. Really interested to hear feedback from #Spring developers.
-
Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.
Mehr von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
@xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity
-
Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.
Mehr von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
@xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity
-
Dive into the latest releases from #Spring 👉 https://bit.ly/3K9wRmf
GA releases of Spring Boot, Spring Security, Spring for GraphQL, Spring Integration, Spring Modulith, Spring REST Docs and Spring Batch.
#Java #SpringBoot #SpringSecurity #SpringFramework #ApacheKafka #AMQP #GraphQL
-
Dive into the latest releases from #Spring 👉 https://bit.ly/3K9wRmf
GA releases of Spring Boot, Spring Security, Spring for GraphQL, Spring Integration, Spring Modulith, Spring REST Docs and Spring Batch.
#Java #SpringBoot #SpringSecurity #SpringFramework #ApacheKafka #AMQP #GraphQL
-
You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.
Learn what #XDEV SSE solves: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.
Learn what #XDEV SSE solves: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
🍃 The next installment of the Road to GA series about a cross-project, collaborative effort on new capabilities for HTTP service clients in #Spring is now live!
https://spring.io/blog/2025/09/23/http-service-client-enhancements
-
🍃 The next installment of the Road to GA series about a cross-project, collaborative effort on new capabilities for HTTP service clients in #Spring is now live!
https://spring.io/blog/2025/09/23/http-service-client-enhancements
-
Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity
-
Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity
-
Spring Security для начинающих: конспект от аутентификации до JWT
На Хабре уже много статей про Spring Security — от кратких заметок до глубоких разборов. В этой статье я решил собрать всё в формате конспект-мануала, который можно читать как пошаговое введение: от базовой аутентификации и фильтров до JWT и OAuth2. Это материал, собранный по официальной документации и дополненный разъяснениями «на простом языке». Я не работал в больших enterprise-командах, поэтому буду рад комментариям и советам от более опытных коллег. Местами я использовал помощь ChatGPT: он помог структурировать материал и сделать стиль более читабельным, ближе к документации.
-
#SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.
A must-read for security-conscious teams: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware @vaadin #Vaadin #OAuth2
-
#SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.
A must-read for security-conscious teams: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware @vaadin #Vaadin #OAuth2
-
Check out what's new in the #Spring community 👉 https://bit.ly/3JyVeZX
The second milestone releases of Spring Boot, Spring Security, Spring Authorization Server, Spring for GraphQL, Spring Session, Spring Integration, Spring REST Docs, Spring Batch and Spring for Apache Pulsar.
#Java #SpringBoot #SpringSecurity SpringFramework #SpringBatch
-
Check out what's new in the #Spring community 👉 https://bit.ly/3JyVeZX
The second milestone releases of Spring Boot, Spring Security, Spring Authorization Server, Spring for GraphQL, Spring Session, Spring Integration, Spring REST Docs, Spring Batch and Spring for Apache Pulsar.
#Java #SpringBoot #SpringSecurity SpringFramework #SpringBatch
-
#SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OpenSource #Vaadin @vaadin
-
#SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OpenSource #Vaadin @vaadin
-
Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.
Code & Docs: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 @vaadin
-
Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.
Code & Docs: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 @vaadin
-
Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.
Read it if #SpringSecurity alone isn’t enough: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware #Vaadin -
Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.
Read it if #SpringSecurity alone isn’t enough: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware #Vaadin -
Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!
Read #JAVAPRO: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!
Read #JAVAPRO: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
🔐 We built it because we needed it – now it’s yours!
We often ran into the same challenge: handling OAuth2/OIDC securely and cleanly with #SpringSecurity.
So we created XDEV SSE – a practical extension born out of real-world needs. It simplifies authentication flows, boosts security, and integrates seamlessly with Vaadin.
-
🔐 We built it because we needed it – now it’s yours!
We often ran into the same challenge: handling OAuth2/OIDC securely and cleanly with #SpringSecurity.
So we created XDEV SSE – a practical extension born out of real-world needs. It simplifies authentication flows, boosts security, and integrates seamlessly with Vaadin.
-
Check out our latest blog post on XDEV SSE! 🔐 Learn how our extension for #SpringSecurity simplifies OAuth2/OIDC handling, improves security, and integrates seamlessly with #Vaadin.
Dive into the code & discover its features: https://xdev.software/news
#Java #OpenSource -
Check out our latest blog post on XDEV SSE! 🔐 Learn how our extension for #SpringSecurity simplifies OAuth2/OIDC handling, improves security, and integrates seamlessly with #Vaadin.
Dive into the code & discover its features: https://xdev.software/news
#Java #OpenSource -
Dive into the latest releases from #Spring 👉 https://bit.ly/44v29Lx
The first milestone release of Spring Vault 4.0; and point releases of Spring Boot, Spring Security, Spring Authorization Server, Spring Session, Spring Integration, Spring Modulith, Spring REST Docs, Spring AMQP, Spring for Apache Kafka, Spring for Apache Pulsar and Spring Web Services.
#Java #SpringBoot #SpringSecurity #SpringModulith #SpringVault
-
Dive into the latest releases from #Spring 👉 https://bit.ly/3STMS0b
GA releases of Spring Boot, Spring Security, Spring Authorization Server, Spring Session, Spring Integration, Spring for GraphQL, Spring AI and Spring Web Services.
-
Dive into the latest releases from #Spring 👉 https://bit.ly/3EJAUTq
First release candidates of Spring Boot, Spring Data 2025.0.0, Spring Security, Spring Authorization Server, Spring Session, Spring Integration, Spring Modulith & Spring Web Services.
#Java #SpringBoot #SpringData #SpringSecurity #SpringModulith #SpringVault #SpringFramework
-
This #InfoQ article provides a detailed solution for registering & authenticating a user through a client-side #JavaScript application using the #SpringSecurity infrastructure, access & refresh tokens.
We explore the process in detail with helpful flow diagrams!
🔗 Get a deeper understanding: https://bit.ly/3DWoKFX
-
Dive into the latest releases from #Spring 👉 https://bit.ly/3Y32ilE
Spring Boot, Spring Security, Spring Authorization Server, Spring for GraphQL, Spring Integration, Spring AMQP, Spring for Apache Kafka and Spring Web Services.
#Java #SpringBoot #SpringFramework #SpringSecurity #SpringBatch #SpringModulith
-
Dive into the latest releases from #Spring 👉 https://bit.ly/3QuNKaD
Releases of: Spring Boot, Spring Security, Spring Authorization Server, Spring Integration, Spring AI and Spring AMQP.
Many of these releases are included in Spring Boot 3.5.0-M2, 3.4.3 & 3.3.9.
#Java #SpringData #SpringCloud #SpringBoot #SpringFramework #SpringSecurity
-
Securing #Vaadin Applications with One-Time Token by @SimonMartinelli
https://martinelli.ch/securing-vaadin-applications-with-one-time-token/