Security & Advanced
The Security filter chain, JWT/OAuth2, async pools, event-driven design and Actuator monitoring.
5 tutorials
01Spring Security Internals: Filter Chain, Authentication, AuthorizationFifteen filters form one security chain where authentication and authorization each do their job — from FilterChainProxy down to SecurityFilterChain config, and why your API suddenly returns 401/403.Advanced36′02JWT and OAuth2: Stateless Authentication in PracticeOpen up JWT's three segments, sign and verify by hand, design dual-token refresh, then walk the OAuth2 authorization-code flow — the standard auth stack for SPA + API.Intermediate55′03Async Tasks, Thread Pools and SchedulingWhy is @Async bad by default? Custom executors, rejection policies, context propagation, graceful shutdown — then @Scheduled's three modes and duplicate execution in a cluster.Intermediate62′04Event-Driven Design: ApplicationEvent and Message QueuesFrom Spring built-in events to transactional and async listeners, then the RabbitMQ vs Kafka trade-off and reliable delivery with a local message table.Advanced80′05Actuator and Observability: Health, Metrics and MonitoringAfter enabling Actuator: custom health checks, exposing metrics to Prometheus, changing log levels at runtime and custom endpoints — making "what is happening in production" answerable.Intermediate60′