Enterprise Security with Spring Authorization Server 1.0 by Rob Winch @ Spring I/O

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ก.ค. 2024
  • Spring I/O 2023 - Barcelona, 18-19 May
    Slides: docs.google.com/presentation/...
    GitHub Repo: github.com/rwinch/spring-ente...
    There are commercial OAuth Authorization Server options available, but none of them can be customized to meet your requirements. Settling is not an option.
    Fortunately, the newly released Spring Authorization Server makes it easy to build a fully customizable OAuth Authorization Server. Building on the time tested foundation of Spring Security, Spring Authorization Server allows you to create your own Authorization Server with the full power of Spring and Spring Security at your fingertips.
    In this talk you will learn how to create your own Authorization Server using Spring Authorization Server. You will also learn how to customize your authorization server using common extension points while following best practices that ensure your Authorization Server is Enterprise ready.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 18

  • @thekontza
    @thekontza ปีที่แล้ว +8

    For future reference: IDEA View -> Appeareance -> Presentation mode + in settings you can spec the pres mode font scaling (175% by default).

    • @datchoob1978
      @datchoob1978 ปีที่แล้ว

      Learned something new today

    • @zartcolwing3218
      @zartcolwing3218 8 หลายเดือนก่อน

      CTRL + ` (backtick - on the left side of the 1) then 5 then 1 : turn your IDE in presentation mode -- same key sequence will return you to normal mode😀

  • @maneshipocrates2264
    @maneshipocrates2264 9 หลายเดือนก่อน

    Well explained indeed.

  • @dekeyserwilly
    @dekeyserwilly 9 หลายเดือนก่อน

    Once again, you made a very informative video.
    Do you have any experience with Spring Authorization Server and Two-Factor Authentication.
    In what way can I implement this. Can you point me in the right direction?
    Thanks.

  • @codingstyle9480
    @codingstyle9480 ปีที่แล้ว

    Is there any user registration end-point by default?

  • @vipinkoul595
    @vipinkoul595 6 หลายเดือนก่อน

    For API's you said access_token, but we have API keys also. When should we use API keys instead of access_token? Can you please help understand?

  • @alexsmart2612
    @alexsmart2612 ปีที่แล้ว

    Not sure why the entirety of the talk was spent talking only about authentication and not authorization.

  • @TheHeartOfTheEvil
    @TheHeartOfTheEvil ปีที่แล้ว +5

    The csrf advice is bad imo, if you're in a browser but you send your jwt in an header instead of a cookie csrf isn't needed.

    • @codeful_dev
      @codeful_dev 7 หลายเดือนก่อน

      I am glad I am not the only one who caught that!

  • @macctosh
    @macctosh ปีที่แล้ว +1

    can't see the code! makes this presentation useless! next time try dark mode, who knows might have helped

    • @peteraleksiev1131
      @peteraleksiev1131 ปีที่แล้ว +19

      How arrogant are you actually? The dude explained everything in a great way and provided you with the github repo......

    • @macctosh
      @macctosh ปีที่แล้ว

      @@peteraleksiev1131 nope... They had enough time to prepare. So there is no excuse for the unreadable font size. Even the people in the attendance kept asking him to increase the font and his answer was ..... "That's as big as I can make it on this laptop" didn't he prep the presentation? what about other presentations? were they all like this? unacceptable!

    • @light.yagami787
      @light.yagami787 ปีที่แล้ว

      lol, just watch it on youtube like the rest of us

    • @freindimania11
      @freindimania11 ปีที่แล้ว

      I can see it perfectly fine - get yourself some glasses

    • @carnelyve866
      @carnelyve866 ปีที่แล้ว +5

      Homo sapiens are really strange species. How anyone can dislike this presentation is beyond me. It was exceptional and beautiful.