Skip to main content

Posts

Showing posts with the label springboot

Spring Security - Authority vs Role

I have spent a lot of time recently trying to understand the difference between Authority and Role in Spring Security.  This is a brief review of what I found. When creating a UserDetailsService or overriding configure(AuthenticationManagerBuilder auth) in the security config class that extends WebSecurityConfigurerAdapter, I basically get complete control over what I populate inside of the UserDetails that is used/returned.  This is important because the UserDetails interface really only cares about how to return one thing: Collection<? extends GrantedAuthority> getAuthorities(); A GrantedAuthority just seems like a glorified String wrapper that names some thing.  The question is... what is that thing? This is where the subtle difference between Authority and Role comes into play. I think that Role is an older thought/construct that automatically gets plugged into Authority if we just create a user with a Role.  But completely forget about the code a...

Spring Security 5 Updates

I've got a bit of time between projects, so I've decided to brush up on Spring Security, as it has been a while since I've tried to follow updates. The first thing I noticed is that when playing around, Spring 5 really doesn't want you to deal with plain text passwords.  This is completely understandable; plain text passwords are BAD and cause bad things to happen in the real world.  Unfortunately, if I'm just trying to play around with the security framework, this can make things a bit clunky.  I've learned there are two ways to work around 1. Do simple inMemoryAuthentication after explicitly calling User.withDefaultPasswordEncoder() to allow plain text passwords while just playing around. 2. Roll a simple/custom UserDetailsService for configure() to use that knows the password doesn't get encryption by prefixing "{noop}" to the password text. (Thanks to ever helpful mkyong for this.)

First thoughts on working with JHipster

I'm working through a sample application with JHipster, and so far, I like it.  The approach and instructions seem straight forward, and the ability to generate domain objects and associated code using jdl is nice.  I've also looked at generating the domain objects for different kinds of databases, and the results are intriguing.  When generating code for mysql (a relational database), we see lombok doing a lot of work to generate boilerplate.  This is not the case if we generate code for mongo (a document-oriented no-sql database).  For mongo, JHipster manually generates getters, setters, equals, hashcode, and even some other builder-type methods.  The important thing here for me is not so much the use of various tools, but more the basic fact that the resulting generated code is fundamentally different. I tend to work in Windows most of the time, and this has become a problem for trying to run databases and other useful tools/images in docker.  I h...

JHipster

In late 2017, JHipster was nominated for / won several awards in the tech innovation space.  It is easy to see why.  This tool automatically generates not only boiler plate code for full stack applications based on spring boot + front end (either react or angular at the time of this writing), but it also generates boiler plate for connecting to a number of databases, tools for front end authentication, and even user management.  Each of these things is a somewhat time consuming task, and having a tool that connects all of these dots out the gate can be extremely useful.  While I suspect many enterprises will struggle to use all of the abilities of a tool like this due to legacy systems, small projects, startups, and people looking to learn about how some of these technologies could definitely benefit from JHipster.  I will hopefully see about tackling a project using JHipster soon.

Great thoughts on learning Spring Boot and why it feels complex

I stumbled across this page from SivaLabs , and I appreciate how it describes the complexity of learning spring by comparing it to learning the complexity of front end technology.  I also feel lost each time I start approaching yet another one of the 36,794 ways to use and configure javascript, and that helps me remember why spring can feel so overwhelming for new people. SivaLabs looks like a great resource for development thoughts, and I look forward to exploring it more.