Deep dive into Spring Security

Covers how Spring Security integrates into the Spring Boot request lifecycle — filter chains, authentication, and authorization mechanics.

Key areas typically probed:

  • SecurityFilterChain vs older WebSecurityConfigurerAdapter approach
  • Filter vs Interceptor — filters operate at Servlet level (before DispatcherServlet); interceptors at Spring MVC level (after)
  • Pre-authentication flows: when identity is established externally (e.g. SSO/token header), AbstractPreAuthenticatedProcessingFilter extracts principal without credential validation
  • AuthenticationManager, AuthenticationProvider, UserDetailsService chain
  • Method-level security (@PreAuthorize, @Secured)

Expect to explain how a request flows through the filter chain, how to configure custom filters, and the difference between authentication and authorization contexts.

asked …
LeaderboardSalaryAccount