Skip to content

Repository files navigation

SecureJwTeaTime

SecureTeaTime is a demo API built with Spring Boot and Spring Security to demonstrate the use of JWT authentication. This project serves as a personal Spring Security template, designed to be a starting point for building secured applications.

This project contains the following features:

  • Login with access & refresh tokens
    • An access token will be returned to the client.
    • A refresh token will be stored in HTTP only cookie.
    • The refresh token can be used to refresh the access token when it is expired.
    • On logout current access token will be blacklisted
    • During authentication the filter checks if token is black-listed, if so access is denied.
  • Account activation via e-mail
  • Password reset: request reset -> receive email -> reset password -> confirmation email

Requirements

  • Java 17+
  • Maven
  • Docker

How to run

Clone the project:

         https://github.com/lvanrooijen/SecureJwTeaTime.git

Build containers:
cd SecureJwTeaTime
docker compose up --build

Run backend:
mvn install
mvn spring-boot:run or play button

What runs where

  • The API will be running on 8080
  • MailDev runs on 1080
  • PG admin runs on 5050

When registering a new server on pg admin you should use SecureJwTeaTime_postgres as the hostname

Demo

play button

About

Spring security setup with JWT -- Access Denied, I'm a Teapot

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages