| name | springboot-security |
| description | Use when configuring Spring Security, implementing JWT/OAuth2 auth, adding role-based access control, or hardening Spring Boot APIs. Do NOT use for general patterns (use springboot-patterns), JPA (use jpa-patterns), or testing (use springboot-tdd). |
| paths | **/*.java, **/build.gradle*, **/pom.xml, **/application*.yml, **/application*.properties |
Spring Boot Security Patterns
๋ฒ์ ๊ฒฝ๊ณ(Security 6 โ 7)์ ํ๋จ ๊ท์น๋ง ๋ด๋๋ค. Spring Security ์ผ๋ฐ ๊ตฌํ ์ง์์ ๋ชจ๋ธ์ ์ด๋ฏธ ์์.
๋ฒ์ ์ปจํ
์คํธ: Spring Security 7 (Boot 4 ๊ธฐ๋ฐ) โ lambda DSL ์ ์ฉ. ํ์ต ๋ฐ์ดํฐ์ ํํ ๊ตฌ๋ฒ์ ๊ด์ฉ๊ตฌ๋ฅผ ์ฐ์ง ๋ง ๊ฒ (์๋ migration ํ).
CRITICAL Rules
- Deny by default โ ๋ช
์์ ์ผ๋ก ํ์ฉํ ๊ฒฝ๋ก๋ง ์ ๊ทผ ๊ฐ๋ฅ
- Never store plaintext passwords โ BCrypt(12+) ๋๋ Argon2 ์ฌ์ฉ
- Never hardcode secrets โ
${ENV_VAR} ๋๋ Vault
- Never trust X-Forwarded-For directly โ ForwardedHeaderFilter + trusted proxy ์ค์ ํ์ (rate limiting์
getRemoteAddr()๋ ๋์ผ)
- Never log tokens, passwords, PII โ ๊ตฌ์กฐํ๋ ๋ก๊น
์์ ๋ฏผ๊ฐ ํ๋ ์ ์ธ
- PREFER OAuth2 Resource Server (
oauth2ResourceServer().jwt()) over custom JWT filter โ ์ธ๋ถ IdP๋ ์์ฒด ๋ฐ๊ธ์ด๋ ๊ฒ์ฆ์ ๊ณต์ ๊ถ์ฅ ๋ฐฉ์. ์ปค์คํ
OncePerRequestFilter๋ ์์ฒด ํ ํฐ ๋ฐ๊ธ๊น์ง ํด์ผ ํ ๋๋ง
Security 7 / Boot 4 Migration
Security 6์์ deprecated์๋ API๊ฐ SS7์์ ์ ๊ฑฐ๋จ. ์ปดํ์ผ ์๋ฌ ๋๋ ์ง์ :
| ์ ๊ฑฐ๋จ (SS6 deprecated โ SS7 removed) | ๋์ฒด |
|---|
๋น-lambda chained DSL .and() | lambda DSL (http.csrf(c -> ...) ํํ) |
authorizeRequests() | authorizeHttpRequests() |
custom DSL์ HttpSecurity#apply(...) | .with(...) |
@EnableGlobalMethodSecurity | @EnableMethodSecurity |
antMatchers() / mvcMatchers() | requestMatchers() |
CSRF Strategy
| App Type | CSRF | Reason |
|---|
| Stateless API (JWT/Bearer) | Disable | Token itself prevents CSRF |
| Session-based web app | Enable | Browser auto-sends cookies |
| Mixed (API + web) | Enable for web paths | Selective protection |
Security Checklist
Gotchas
- โ
authorizeRequests(), antMatchers(), .and() ์์ฑ (SS7์์ ์ ๊ฑฐ๋จ) โ migration ํ ์ฐธ์กฐ
- โ
permitAll()์ ๋์ ๋งค์ฒ ๋ค์ ์ ์ธ โ ์์ ์ค์, ๊ตฌ์ฒด์ ๋งค์นญ ๋จผ์
- โ
@PreAuthorize์์ ํ๋์ฝ๋ฉ๋ role ๋ฌธ์์ด โ ์์ ๋๋ enum ์ฌ์ฉ
- โ JWT ๋น๋ฐํค๋ฅผ application.yml์ ์ง์ ์์ฑ โ ํ๊ฒฝ๋ณ์ ํ์
- โ ์ปค์คํ
JWT ํํฐ๋ถํฐ ์์ฑ โ OAuth2 Resource Server๊ฐ ๊ธฐ๋ณธ ์ ํ์ง
References