Deep dive into Spring Security
Covers how Spring Security integrates into the Spring Boot request lifecycle — filter chains, authentication, and authorization mechanics.
Key areas typically probed:
SecurityFilterChainvs olderWebSecurityConfigurerAdapterapproach- Filter vs Interceptor — filters operate at Servlet level (before DispatcherServlet); interceptors at Spring MVC level (after)
- Pre-authentication flows: when identity is established externally (e.g. SSO/token header),
AbstractPreAuthenticatedProcessingFilterextracts principal without credential validation AuthenticationManager,AuthenticationProvider,UserDetailsServicechain- Method-level security (
@PreAuthorize,@Secured)
Expect to explain how a request flows through the filter chain, how to configure custom filters, and the difference between authentication and authorization contexts.
asked …