Securing Spring Boot Microservices with Spring Security
Overview Basically, our microservices are secured this way : The user provides his credentials via a public endpoint If authenticated, the server returns an authentication token (JWT) The JWT is attached to each subsequent request via an HTTP header: Authorization:Bearer TOKEN You can find the source code at https://github.com/vedrax-admin/spring-microservices User Microservice This microservice uses a MySQL database. We begin by creating the Account table: Below is a script to insert some dummy data: The Account entity will be created using JPA: The account repository: User Principal We create a class named UserPrincipal which implements UserDetails . In order to be accessible by all microservices, this class is located in our shared module. JWT Token Service This service is responsible for creating expiring JWT. We can also parse a JWT for getting the UserPrincipal . We use the io.jsonwebtoken dependency for that. Account Service...