Skip to content
Back to skills

Springboot Security

ASecurity

Use when spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Triggers on \"springboot-security\", \"springboot security\", \"security\".

  • 2 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 19, 2026
ai-agentsgojavasqldjangospringtestingapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add majinmagros/magros.ai-skills --skill springboot-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Springboot Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Springboot Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/majinmagros-springboot-security/badge)](https://www.skillsdirectory.com/skills/majinmagros-springboot-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: springboot-security
description: "Use when spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Triggers on \"springboot-security\", \"springboot security\", \"security\"."
metadata:
  origin: ECC
---

# Spring Boot Security Review

Deny by default: validate inputs, least privilege, secure-by-configuration. Detalhes em `references/`.

## When to Activate

- Adding authentication (JWT, OAuth2, session-based)
- Implementing authorization (@PreAuthorize, role-based access)
- Validating user input (Bean Validation, custom validators)
- Configuring CORS, CSRF, or security headers
- Managing secrets (Vault, environment variables)
- Adding rate limiting or scanning dependencies for CVEs

## When NOT to Use

- Other stacks (use `quarkus-security`, `django-security`, `laravel-security`, etc.)
- General security checklist, not Spring-specific (use `security-review`)
- Spring Boot architecture and API patterns (use `springboot-patterns`)
- Spring Boot testing (use `springboot-tdd`)

## Core Principles

1. **Deny by default** — expose only required scopes; guards on every sensitive path
2. **Stateless auth, hashed secrets** — Bearer JWT + BCrypt/Argon2, never plaintext
3. **Validate at the boundary** — `@Valid` DTOs, parameterized queries, no concatenation
4. **Externalize secrets** — env/Vault placeholders; nothing committed
5. **Defense in depth** — headers, CORS allowlist, rate limits, scanned dependencies

## Example

```java
public record CreateUserDto(
    @NotBlank @Size(max = 100) String name,
    @NotBlank @Email String email
) {}

@PostMapping("/users")
@PreAuthorize("hasRole('ADMIN')")
public ResponseEntity<UserDto> createUser(@Valid @RequestBody CreateUserDto dto) {
  return ResponseEntity.status(HttpStatus.CREATED).body(userService.create(dto));
}
```

## References

- `references/auth.md` — JWT filter, @PreAuthorize, BCrypt password encoding
- `references/input-data.md` — Bean Validation, SQL injection, uploads, PII logging
- `references/http-defense.md` — CSRF, secrets, headers, CORS, Bucket4j limits, CVEs

## Checklist

- [ ] Tokens validated and expired; authorization on every sensitive path
- [ ] All inputs validated; no string-concatenated SQL
- [ ] CSRF posture correct for app type; secrets externalized
- [ ] Security headers + restrictive CORS configured; APIs rate-limited
- [ ] Dependencies scanned; logs free of secrets and PII

Files in this skill

  • SKILL.md2.4 KB
  • references/auth.md2 KB
  • references/http-defense.md3.3 KB
  • references/input-data.md1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…