spring-security
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseWhen to use this skill
When to use this skill
Use this skill whenever the user wants to:
- 用 Spring Security 配置认证、授权、会话与安全头
- 集成 OAuth2、JWT、方法安全与 CSRF
Use this skill whenever the user wants to:
- Configure authentication, authorization, sessions, and security headers with Spring Security
- Integrate OAuth2, JWT, method security, and CSRF
How to use this skill
How to use this skill
- 配置:SecurityFilterChain、UserDetailsService、PasswordEncoder;登录/登出与异常处理。
- 进阶:JWT、OAuth2 客户端/资源服务器;@PreAuthorize、CORS。
- 参考:https://docs.spring.io/spring-security/reference/
- Configuration: SecurityFilterChain, UserDetailsService, PasswordEncoder; login/logout and exception handling.
- Advanced: JWT, OAuth2 client/resource server; @PreAuthorize, CORS.
- Reference: https://docs.spring.io/spring-security/reference/
Best Practices
Best Practices
- 密码加密、会话与 Cookie 安全;最小权限与角色设计。
- 生产用 HTTPS 与安全头;敏感路径保护。
- Password encryption, session and cookie security; least privilege and role design.
- Use HTTPS and security headers in production; protect sensitive paths.
Keywords
Keywords
spring security, 认证, 授权, JWT, OAuth2
spring security, authentication, authorization, JWT, OAuth2
能力边界
Scope of Capabilities
✅ 适用场景
✅ Applicable Scenarios
- 当你需要使用此技能对应的技术栈时
- 当项目需要遵循最佳实践时
- 当需要快速上手或深入理解核心概念时
- When you need to use the tech stack corresponding to this skill
- When the project needs to follow best practices
- When you need to get started quickly or gain an in-depth understanding of core concepts
⚠️ 需要注意
⚠️ Notes
- 复杂业务逻辑需要结合具体场景调整
- 性能优化需要根据实际数据量评估
- Complex business logic needs to be adjusted based on specific scenarios
- Performance optimization needs to be evaluated based on actual data volume
❌ 不适用场景
❌ Inapplicable Scenarios
- 不相关的技术栈或框架
- 需要完全自定义的特殊场景
- Unrelated tech stacks or frameworks
- Special scenarios requiring full customization
常见陷阱 (Gotchas)
Common Pitfalls (Gotchas)
- 版本兼容性:注意框架版本与依赖库的兼容性,不同版本 API 可能有差异
- 配置文件格式:配置文件格式错误是最常见的问题,建议使用编辑器的语法检查
- 环境变量:确保所有必要的环境变量已正确设置,敏感信息不要硬编码
- 依赖冲突:多版本共存时注意依赖冲突,使用 lock 文件锁定版本
- 性能陷阱:大数据量场景下注意性能优化,避免 N+1 查询等常见问题
- Version Compatibility: Pay attention to the compatibility between framework versions and dependent libraries; APIs may vary across different versions
- Configuration File Format: Configuration file format errors are the most common issue; it is recommended to use the editor's syntax check
- Environment Variables: Ensure all necessary environment variables are set correctly; do not hardcode sensitive information
- Dependency Conflicts: Pay attention to dependency conflicts when multiple versions coexist; use lock files to lock versions
- Performance Pitfalls: Pay attention to performance optimization in large data volume scenarios; avoid common issues such as N+1 queries
使用流程
Usage Process
Step 1: 环境准备
Step 1: Environment Preparation
确保开发环境已安装必要的依赖和工具。
Ensure the development environment has the necessary dependencies and tools installed.
Step 2: 配置初始化
Step 2: Configuration Initialization
根据项目需求进行基础配置。
Perform basic configuration according to project requirements.
Step 3: 核心功能使用
Step 3: Core Function Usage
按照示例代码实现核心功能。
Implement core functions according to sample code.
Step 4: 测试验证
Step 4: Testing and Verification
运行测试确保功能正常。
Run tests to ensure functions work properly.
Step 5: 部署上线
Step 5: Deployment and Launch
完成开发后进行部署和监控。
Deploy and monitor after development is completed.