Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
joaquimscosta avatar

Spring Boot Security

  • 1 installs
  • 21 repo stars
  • Updated August 5, 2026
  • joaquimscosta/arkhe-claude-plugins

Implements Spring Security 7 for Spring Boot 4: authentication, authorization, OAuth2/JWT resource servers, method security, and the mandatory Lambda DSL migration.

About

Implements authentication and authorization in Spring Boot 4 with Spring Security 7's mandatory Lambda DSL, SecurityFilterChain beans, and @PreAuthorize. A developer uses it to secure endpoints or migrate off removed Spring Security APIs.

  • Lambda DSL and SecurityFilterChain migration
  • OAuth2/JWT resource server and method security

Spring Boot Security by the numbers

  • 1 all-time installs (skills.sh)
  • Ranked #1,834 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/joaquimscosta/arkhe-claude-plugins --skill spring-boot-security

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1
repo stars21
Last updatedAugust 5, 2026
Repositoryjoaquimscosta/arkhe-claude-plugins

What it does

Implements Spring Security 7 for Spring Boot 4: authentication, authorization, OAuth2/JWT resource servers, method security, and the mandatory Lambda DSL migration.

Files

SKILL.mdMarkdownGitHub ↗

Spring Security 7 for Spring Boot 4

Implements authentication and authorization with Spring Security 7's mandatory Lambda DSL.

Critical Breaking Changes

Removed APIReplacementStatus
and() methodLambda DSL closuresRequired
authorizeRequests()authorizeHttpRequests()Required
antMatchers()requestMatchers()Required
WebSecurityConfigurerAdapterSecurityFilterChain beanRequired
@EnableGlobalMethodSecurity@EnableMethodSecurityRequired

Core Workflow

1. Create SecurityFilterChain → 2. Define authorization → 3. Configure authentication → 4. Add method security → 5. Handle CORS/CSRF

See WORKFLOW.md for detailed step-by-step instructions with code examples.

Quick Patterns

See EXAMPLES.md for complete working examples including:

  • REST API Security with JWT/OAuth2 (Java + Kotlin)
  • Form Login with Session Security and CSRF
  • Method Security with @PreAuthorize and SpEL
  • CORS Configuration for cross-origin APIs
  • Password Encoder (Argon2 for Security 7)

Spring Boot 4 Specifics

  • Lambda DSL is mandatory (no and() chaining)
  • Argon2 password encoder: Argon2PasswordEncoder.defaultsForSpring7()
  • CSRF for SPAs: CookieCsrfTokenRepository.withHttpOnlyFalse()
  • @EnableMethodSecurity replaces @EnableGlobalMethodSecurity

Detailed References

  • Workflow: See WORKFLOW.md for detailed step-by-step security configuration
  • Examples: See EXAMPLES.md for complete working code examples
  • Troubleshooting: See TROUBLESHOOTING.md for common issues and Boot 4 migration
  • Security Configuration: See references/SECURITY-CONFIG.md for complete SecurityFilterChain patterns
  • Authentication: See references/AUTHENTICATION.md for UserDetailsService, password encoding
  • JWT/OAuth2: See references/JWT-OAUTH2.md for resource server, token validation

Related Skills

NeedSkill
Testing secured endpointsspring-boot-testing
Actuator endpoint securityspring-boot-observability
Dependency verificationspring-boot-verify

Anti-Pattern Checklist

Anti-PatternFix
Using and() chainingUse Lambda DSL closures
antMatchers()Replace with requestMatchers()
authorizeRequests()Replace with authorizeHttpRequests()
CSRF disabled without JWTKeep CSRF for session-based auth
Hardcoded credentialsUse environment variables or Secret Manager
permitAll() on sensitive endpointsAudit all permit rules
Missing authenticated() defaultEnd with .anyRequest().authenticated()

Critical Reminders

1. Lambda DSL is mandatory — No more and() chaining in Security 7 2. Order matters — More specific requestMatchers before general ones 3. CSRF for sessions — Only disable for stateless JWT APIs 4. Method security needs enabling — Add @EnableMethodSecurity 5. Test security configuration — Use @WithMockUser and JWT test support (see spring-boot-testing)

Related skills

Securityappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.