Speaker

Daniel Garnier-Moiroux
Spring

Daniel Garnier is a software engineer on the Spring team, working on Spring Security and Spring AI.

He's one of the maintainers of the Java MCP SDK.

View
Authorization in Spring Security: permissions, roles and beyond
Conference (BEGINNER level)
Auditorium

When creating Spring Boot apps, Spring Security is the go-to choice for all your security use-cases. It offers protections against exploits, authentication (who is the user?) and authorization (are they allowed to do X?) capabilities. Basic authorization features, such as hasRole(...), are easy to implement, but things quickly become complicated when you have more advanced use-cases.

Many operations must be architected correctly to provide secure and robust authorization, in multiple phases. During the initial login phase, the relevant information about the user is extracted, transformed and stored, for example user data from OpenID claims. Then, for authorization, “policy decision” and “policy enforcement” are defined within the context of an operation: where are the authorization decisions made? Lastly, strategies are implemented in code to produce those authorization decisions.

Through live-coded examples, you will build a solid, foundational understanding for all your authorization architecture. You will get an overview of all the access control patterns you can apply with Spring Security. And you will get practical advice on different authorization mechanisms available, and their tradeoffs.

More
View
Spring Documentary World Premiere at Devoxx UK
Auditorium

Devoxx UK ticket holders can attend using their conference ticket. Not attending Devoxx UK? Register via this event page to secure your spot.

​Cult.Repo — the team behind cinematic documentaries on React, Node.js, Kubernetes, and more — brings its latest film to Devoxx UK for its world premiere.

​Spring traces the full arc of one of open source's most consequential projects: from its origins as a quiet rebellion against enterprise Java complexity, through the paradigm shift of Spring Boot, into the microservices era and the cloud-native architectures that now run beneath some of the world's most critical software.

​It's a story about technical vision, community, and what it takes to stay relevant across two decades of relentless change.

​After the film, there will be a panel featuring Josh Long, Marit van Dijik, and Steve Poole.

​Doors open at 6:30pm

​Film starts at 7pm

​Panel at 8pm

More

Searching for speaker images...