Похожие чаты

Hi, I wanted to add authorization in a spring boot

REST API. I used jwt tokens in a cookie with an interceptor check if the user is authorized or not and i have to call a custom function in each controller with the request as parameter to get the user details. Does this implementation has any issue? Should I move to spring security with a custom filter instead? Would it be easy to get the user details if spring security is used instead?

6 ответов

22 просмотра

It sounds good, but almost identical thing is done by spring security. Personally I recommend to not waste your time on building custom homebrew solution, but rather spend this time on learning spring security. The benefits: - spring security is more mature - it's both more flexible and better tested than what you'll create - it's ubiquitous, so by learning how to do it with spring security, you'll have a highly relevant skill in your skill set - it's better designed, believe me)) think of how much code you would need to change in your custom solution if you had to add new rule like "user should have ABC_RW role for doing POST,DELETE,PUT on url /a/b/c/*/protected/** "

Ajith- Автор вопроса
Dmytro Buryak
It sounds good, but almost identical thing is done...

Spring security was an overkill for the project. Thats why i decided to go with a custom solution. I don't need roles and all. I will spend some time to learn spring security more. Thank you :)

Ajith- Автор вопроса
Ajith
?

He thinks that you're using basic authentication instead of implementing something that is more secure.

Ajith- Автор вопроса
Sander Koenders
He thinks that you're using basic authentication i...

What would be more secure? I was using jwt tokens with secure cookies.

Похожие вопросы

Обсуждают сегодня

Господа, а что сейчас вообще с рынком труда на делфи происходит? Какова ситуация?
Rꙮman Yankꙮvsky
29
А вообще, что может смущать в самой Julia - бы сказал, что нет единого стандартного подхода по многим моментам, поэтому многое выглядит как "хаки" и произвол. Короче говоря, с...
Viktor G.
2
@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Гайс, вопрос для разносторонее развитых: читаю стрим с юарта, нада выделять с него фреймы с определенной структурой, если ли чо готовое, или долбаться с ринг буффером? нада у...
Vitaly
9
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Карта сайта