spring-security

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

When to use this skill

When to use this skill

Use this skill whenever the user wants to:
  • 用 Spring Security 配置认证、授权、会话与安全头
  • 集成 OAuth2、JWT、方法安全与 CSRF
Use this skill whenever the user wants to:
  • Configure authentication, authorization, sessions, and security headers with Spring Security
  • Integrate OAuth2, JWT, method security, and CSRF

How to use this skill

How to use this skill

  1. 配置:SecurityFilterChain、UserDetailsService、PasswordEncoder;登录/登出与异常处理。
  2. 进阶:JWT、OAuth2 客户端/资源服务器;@PreAuthorize、CORS。
  3. 参考https://docs.spring.io/spring-security/reference/
  1. Configuration: SecurityFilterChain, UserDetailsService, PasswordEncoder; login/logout and exception handling.
  2. Advanced: JWT, OAuth2 client/resource server; @PreAuthorize, CORS.
  3. Reference: https://docs.spring.io/spring-security/reference/

Best Practices

Best Practices

  • 密码加密、会话与 Cookie 安全;最小权限与角色设计。
  • 生产用 HTTPS 与安全头;敏感路径保护。
  • Password encryption, session and cookie security; least privilege and role design.
  • Use HTTPS and security headers in production; protect sensitive paths.

Keywords

Keywords

spring security, 认证, 授权, JWT, OAuth2
spring security, authentication, authorization, JWT, OAuth2

能力边界

Scope of Capabilities

✅ 适用场景

✅ Applicable Scenarios

  • 当你需要使用此技能对应的技术栈时
  • 当项目需要遵循最佳实践时
  • 当需要快速上手或深入理解核心概念时
  • When you need to use the tech stack corresponding to this skill
  • When the project needs to follow best practices
  • When you need to get started quickly or gain an in-depth understanding of core concepts

⚠️ 需要注意

⚠️ Notes

  • 复杂业务逻辑需要结合具体场景调整
  • 性能优化需要根据实际数据量评估
  • Complex business logic needs to be adjusted based on specific scenarios
  • Performance optimization needs to be evaluated based on actual data volume

❌ 不适用场景

❌ Inapplicable Scenarios

  • 不相关的技术栈或框架
  • 需要完全自定义的特殊场景
  • Unrelated tech stacks or frameworks
  • Special scenarios requiring full customization

常见陷阱 (Gotchas)

Common Pitfalls (Gotchas)

  1. 版本兼容性:注意框架版本与依赖库的兼容性,不同版本 API 可能有差异
  2. 配置文件格式:配置文件格式错误是最常见的问题,建议使用编辑器的语法检查
  3. 环境变量:确保所有必要的环境变量已正确设置,敏感信息不要硬编码
  4. 依赖冲突:多版本共存时注意依赖冲突,使用 lock 文件锁定版本
  5. 性能陷阱:大数据量场景下注意性能优化,避免 N+1 查询等常见问题
  1. Version Compatibility: Pay attention to the compatibility between framework versions and dependent libraries; APIs may vary across different versions
  2. Configuration File Format: Configuration file format errors are the most common issue; it is recommended to use the editor's syntax check
  3. Environment Variables: Ensure all necessary environment variables are set correctly; do not hardcode sensitive information
  4. Dependency Conflicts: Pay attention to dependency conflicts when multiple versions coexist; use lock files to lock versions
  5. Performance Pitfalls: Pay attention to performance optimization in large data volume scenarios; avoid common issues such as N+1 queries

使用流程

Usage Process

Step 1: 环境准备

Step 1: Environment Preparation

确保开发环境已安装必要的依赖和工具。
Ensure the development environment has the necessary dependencies and tools installed.

Step 2: 配置初始化

Step 2: Configuration Initialization

根据项目需求进行基础配置。
Perform basic configuration according to project requirements.

Step 3: 核心功能使用

Step 3: Core Function Usage

按照示例代码实现核心功能。
Implement core functions according to sample code.

Step 4: 测试验证

Step 4: Testing and Verification

运行测试确保功能正常。
Run tests to ensure functions work properly.

Step 5: 部署上线

Step 5: Deployment and Launch

完成开发后进行部署和监控。
Deploy and monitor after development is completed.