agentsclimarketplace

Spring boot security

Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/spring-boot-security

🧠 The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.

Install
npx -y skills add ComeOnOliver/skillshub --skill spring-boot-security

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Spring Security 6+ standards, Lambda DSL, and Hardening. Use when configuring Spring Security 6+, OAuth2, JWT, or security hardening in Spring Boot. (triggers: **/*SecurityConfig.java, **/*Filter.java, security-filter-chain, lambda-dsl, csrf, cors)

SKILL.md

2.0 KB, 415 tokens by cl100k_base, as published. Nobody here has run it

Spring Boot Security Standards

Priority: P0 (CRITICAL)

Implementation Guidelines

Configuration (Spring Security 6+)

  • Lambda DSL: ALWAYS use Lambda DSL.
  • SecurityFilterChain: Expose as @Bean. Do not extend WebSecurityConfigurerAdapter.
  • Statelessness: Enforce SessionCreationPolicy.STATELESS for REST APIs.

Golden Snippet

See Security Configuration for full SecurityFilterChain example.

Authentication vs Authorization

  • Authentication: Validation of credentials (Who are you?). Use AuthenticationManager or JwtDecoder.
  • Authorization: Verification of access rights (Can you do this?). Use @PreAuthorize.

JWT Best Practices

  • Algorithm: Enforce RS256 or HS256. Reject none algorithm.
  • Claims: Validate iss, aud, and exp.
  • Tokens: Short-lived access tokens (15m), secure refresh tokens (httpOnly cookie).

Hardening Checklist

  • CSRF: Disabled for pure APIs? Enabled + Cookie for Browser Apps?
  • CORS: Specific origins permitted? No * with credentials?
  • Headers: HSTS, Content-Type-Options, X-Frame-Options enabled?
  • Secrets: No hardcoded keys? Loaded from Vault/Env?
  • Rate Limiting: Applied on login/expensive endpoints?
  • Dependencies: Scanned for CVEs?

Anti-Patterns

  • No Adapter: Use SecurityFilterChain bean instead of extending legacy classes.
  • No .and(): Use Lambda DSL for configuration.
  • No Secrets: Load from Vault or Environment variables (never git).
  • No antMatchers: Use requestMatchers (Spring Security 6+).

References

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.