Back to skills
SKILL.md
Springboot Security
ASecurityUse when spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Triggers on \"springboot-security\", \"springboot security\", \"security\".
- 2 stars
- 0 votes
- 0 copies
- 2 views
- Added September 19, 2026
Works with
Security analysis
100/100Pro scans all 4 files and shows the line behind each finding
npx -y skills add majinmagros/magros.ai-skills --skill springboot-security --agent claude-codeAre you the author of Springboot Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/majinmagros-springboot-security)---
name: springboot-security
description: "Use when spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Triggers on \"springboot-security\", \"springboot security\", \"security\"."
metadata:
origin: ECC
---
# Spring Boot Security Review
Deny by default: validate inputs, least privilege, secure-by-configuration. Detalhes em `references/`.
## When to Activate
- Adding authentication (JWT, OAuth2, session-based)
- Implementing authorization (@PreAuthorize, role-based access)
- Validating user input (Bean Validation, custom validators)
- Configuring CORS, CSRF, or security headers
- Managing secrets (Vault, environment variables)
- Adding rate limiting or scanning dependencies for CVEs
## When NOT to Use
- Other stacks (use `quarkus-security`, `django-security`, `laravel-security`, etc.)
- General security checklist, not Spring-specific (use `security-review`)
- Spring Boot architecture and API patterns (use `springboot-patterns`)
- Spring Boot testing (use `springboot-tdd`)
## Core Principles
1. **Deny by default** — expose only required scopes; guards on every sensitive path
2. **Stateless auth, hashed secrets** — Bearer JWT + BCrypt/Argon2, never plaintext
3. **Validate at the boundary** — `@Valid` DTOs, parameterized queries, no concatenation
4. **Externalize secrets** — env/Vault placeholders; nothing committed
5. **Defense in depth** — headers, CORS allowlist, rate limits, scanned dependencies
## Example
```java
public record CreateUserDto(
@NotBlank @Size(max = 100) String name,
@NotBlank @Email String email
) {}
@PostMapping("/users")
@PreAuthorize("hasRole('ADMIN')")
public ResponseEntity<UserDto> createUser(@Valid @RequestBody CreateUserDto dto) {
return ResponseEntity.status(HttpStatus.CREATED).body(userService.create(dto));
}
```
## References
- `references/auth.md` — JWT filter, @PreAuthorize, BCrypt password encoding
- `references/input-data.md` — Bean Validation, SQL injection, uploads, PII logging
- `references/http-defense.md` — CSRF, secrets, headers, CORS, Bucket4j limits, CVEs
## Checklist
- [ ] Tokens validated and expired; authorization on every sensitive path
- [ ] All inputs validated; no string-concatenated SQL
- [ ] CSRF posture correct for app type; secrets externalized
- [ ] Security headers + restrictive CORS configured; APIs rate-limited
- [ ] Dependencies scanned; logs free of secrets and PII
Files in this skill
- SKILL.md
- references/auth.md
- references/http-defense.md
- references/input-data.md
Attribution
Comments
Loading comments…