Skip to main content
  • Book
  • © 2019

Pro Spring Security

Securing Spring Framework 5 and Boot 2-based Java Applications

Apress
  • Updates a unique and pragmatic book on Spring security
  • Updated for Spring Boot 2 and Spring Framework 5
  • Written by a Spring certified developer expert

Buy it now

Buying options

eBook USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Other ways to access

This is a preview of subscription content, log in via an institution to check for access.

Table of contents (9 chapters)

  1. Front Matter

    Pages i-xviii
  2. The Scope of Security

    • Carlo Scarioni, Massimo Nardone
    Pages 1-14
  3. Introducing Spring Security

    • Carlo Scarioni, Massimo Nardone
    Pages 15-34
  4. Setting Up the Scene

    • Carlo Scarioni, Massimo Nardone
    Pages 35-68
  5. Spring Security Architecture and Design

    • Carlo Scarioni, Massimo Nardone
    Pages 69-116
  6. Web Security

    • Carlo Scarioni, Massimo Nardone
    Pages 117-158
  7. Configuring Alternative Authentication Providers

    • Carlo Scarioni, Massimo Nardone
    Pages 159-219
  8. Business Object Security with ACLs

    • Carlo Scarioni, Massimo Nardone
    Pages 221-277
  9. Customizing and Extending Spring Security

    • Carlo Scarioni, Massimo Nardone
    Pages 279-344
  10. Integrating Spring Security with Other Frameworks and Languages

    • Carlo Scarioni, Massimo Nardone
    Pages 345-399
  11. Back Matter

    Pages 401-410

About this book

Build and deploy secure Spring Framework and Spring Boot-based enterprise Java applications with the Spring Security Framework. This book explores a comprehensive set of functionalities to implement industry-standard authentication and authorization mechanisms for Java applications.


Pro Spring Security, Second Edition has been updated to incorporate the changes in Spring Framework 5 and Spring Boot 2. It is an advanced tutorial and reference that guides you through the implementation of the security features for a Java web application by presenting consistent examples built from the ground up.

This book also provides you with a broader look into Spring security by including up-to-date use cases such as building a security layer for RESTful web services and Grails applications.


What You Will Learn
  • Explore the scope of security and how to use the Spring Security Framework
  • Master Spring security architecture and design 
  • Secure the web tier in Spring 
  • Work with alternative authentication providers
  • Take advantage of business objects and logic security
  • Extend Spring security with other frameworks and languages
  • Secure the service layer



Who This Book Is For
Experienced Spring and Java developers with prior experience in building Spring Framework or Boot-based applications.

Authors and Affiliations

  • Surbiton, UK

    Carlo Scarioni

  • HELSINKI, Finland

    Massimo Nardone

About the authors

Carlo Scarioni is a passionate software developer, motivated by learning and applying innovative and interesting software development tools, techniques and methodologies, his professional objectives are the following.  To be in a technology-oriented enterprise where the technical staff is the soul of the company. To be in an important IT team. To be able to design and develop state of the art software. To be able to apply new knowledge every day, in innovative ways, and with a great degree of freedom. To architect, design and develop software that uses the best practices of the field. To play with the latest technologies, learn every day and participate in the research and innovation of software products. Specialties: TDD, object-oriented principles and design patterns, Java/JEE, Spring, application servers, SQL and NoSQL (MongoDB), multithreading, messaging, enterprise integration patterns, Ruby, and RoR.  Certifications are Sun Certified Enterprise Architect (Part I), Sun Certified Java Programmer, Sun Certified Business Component Developer, SpringSource Certified Professional, and IBM SOA Certified Associate.


Massimo Nardone has more than 24 years of experience in security, web/mobile development, cloud, and IT architecture. His true IT passions are security and Android. He has been programming and teaching how to program with Android, Perl, PHP, Java, VB, Python, C/C++, and MySQL for more than 20 years. He holds an M.Sc. degree in computing science from the University of Salerno, Italy. During his career, he has worked as a project manager, software engineer, research engineer, chief security architect, information security manager, PCI/SCADA auditor, and senior lead IT security/cloud/SCADA architect.


His technical skills include security, Android, cloud, Java, MySQL, Drupal, Cobol, Perl, web and mobile development, MongoDB, D3, Joomla!, Couchbase, C/C++, WebGL, Python, Pro Rails, Django CMS, Jekyll, and Scratch. He has served as a visiting lecturer and supervisor for exercises at the Networking Laboratory of the Helsinki University of Technology (Aalto University). He holds four international patents (PKI, SIP, SAML, and Proxy areas). He currently works as chief information security officer (CISO) for Cargotec Oyj, and he is a member of the ISACA Finland Chapter Board. Massimo has reviewed more than 45 IT books for different publishers and has coauthored Pro JPA 2 in Java EE 8 (Apress, 2018), Beginning EJB in Java EE 8 (Apress, 2018), and Pro Android Games (Apress, 2015).



Bibliographic Information

Buy it now

Buying options

eBook USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Other ways to access