SecureTeaTime is a demo API built with Spring Boot and Spring Security to demonstrate the use of JWT authentication. This project serves as a personal Spring Security template, designed to be a starting point for building secured applications.
- Login with access & refresh tokens
- An access token will be returned to the client.
- A refresh token will be stored in HTTP only cookie.
- The refresh token can be used to refresh the access token when it is expired.
- On logout current access token will be blacklisted
- During authentication the filter checks if token is black-listed, if so access is denied.
- Account activation via e-mail
- Password reset: request reset -> receive email -> reset password -> confirmation email
- Java 17+
- Maven
- Docker
Clone the project:
https://github.com/lvanrooijen/SecureJwTeaTime.git
Build containers:
cd SecureJwTeaTime
docker compose up --build
Run backend:
mvn install
mvn spring-boot:run
or
When registering a new server on pg admin you should use
SecureJwTeaTime_postgresas the hostname
