Authentication vs Authorization
In previous weeks of Network Computing 2, we explored the internal architecture of Spring Boot, the lifecycle of Beans, relational persistence with Spring Data JPA, and building dynamic views with Server-Side Rendering (SSR) via Thymeleaf.
Encoding, Encryption, and Hashing
One of the most frequent misconceptions in software engineering is using "encoding", "encryption", and "hashing" interchangeably. As Laurențiu Spilcă highlights in his Spring Security lectures, each of these processes serves a fundamentally different mathematical and operational purpose:
Spring Security Architecture
To master Spring Security rather than relying on copy-pasting configurations, we must examine how the framework intercepts and processes every incoming HTTP request inside the Servlet container (Apache Tomcat):
Authorities vs. Roles
Once a user is authenticated, Spring Security evaluates their privileges to determine whether they are authorized to access given endpoints or execute specific methods.
Hands-on Lab: Spring Security & JPA
In the previous conceptual guides (Authentication vs. Authorization, Cryptography, Spring Security Architecture, and Authorities vs. Roles), we examined the theoretical architecture of access control, the filter chain (SecurityFilterChain), the role of AuthenticationManager, and password hash validation via PasswordEncoder.
Weekly Slides
Official presentation slides for Week 9: Spring Security Fundamentals, Authentication vs. Authorization, Web Cryptography and BCrypt Hashing, SecurityFilterChain Internal Architecture, and Access Control Model with GrantedAuthority and Roles.