Deesha Tech Academy
Menu
DTA-08AvailableJavaSpring BootSpring SecurityJWTOAuth2Keycloak

Spring Security

Put authentication and authorisation on a real API without inventing your own

Fee
₹2,400
Duration
12 guided hours
Level
Core
Mode
Online / Offline
ShareWhatsAppEmail

Designed for

  • Developers who have shipped an API with no authentication on it
  • Backend engineers who copied a JWT filter from a blog post
  • Anyone who has been asked "how do you handle roles" in an interview

Course curriculum

5 progressive modules

Duration: 12 guided hours

  1. Foundation
  2. Intermediate
  3. Advanced
  1. FoundationSessions 1–2

    The filter chain, and what actually happens on a request

    • The security filter chain in order, and where your code sits in it
    • Authentication compared with authorisation, precisely
    • SecurityContext, principals and how they propagate
    • Configuring HTTP security without copying a config you cannot read
    • Why the default configuration blocks everything, and what that tells you

    What you will build

    One endpoint secured and one left open, with the filter chain printed and each filter's job named.

    Module 1

Learning outcomes

What you will be able to do

  1. 01Explain what each filter in the security chain does before your controller runs
  2. 02Store credentials so that a database leak does not reveal passwords
  3. 03Issue and validate JWTs, and describe honestly what revocation costs
  4. 04Enforce ownership rules at the query rather than after loading the data
View all 6 learning outcomes
  • Recognise insecure direct object references and mass assignment in review
  • Write tests that fail when an endpoint loses its authorisation

Batches

Choose a schedule that works for you

No dates yet

Tell us the schedule that would work

We plan batches around demand. Weekend, morning and intensive formats open when enough people ask for them.

Register your interest

Who teaches this

Learn with experienced practitioners

All trainers and mentors
  • Vishal Shah

    Vishal Shah

    Founder & Principal Trainer

    Two decades building and teaching commerce, banking and cloud platforms — still writing code

    • Java & Spring Boot microservices
    • TypeScript, React, Angular & Next.js
    • Composable commerce (commercetools)
    Full profile →

Detailed course information

Full course brief

Security is the part of a backend most often copied rather than understood. A JWT filter from a blog post works on the happy path and fails in ways nobody notices until an audit.

This course is short and adversarial. You secure an API, then attack it from a second terminal, then fix what broke — and you finish able to say why each control is there.

Who this is for

You need a working Spring Boot API. If you do not have one, Spring Boot & REST APIs comes first and builds the service you will secure here.

Where it leads

Group three of Backend Developer — Java and part of Full-Stack Developer — Java.

Get batch details

Tell us the schedule that would suit you and we will let you know when a batch opens.

This website does not store or send these details. Your email or WhatsApp app will open with the message ready for you to review and send.

Where this leads

Need help deciding?

Ask about the curriculum, delivery options or the next batch.

Talk to Academy
Enquire