Prev Next

Spring / Spring Boot 4 Basics Interview Questions

What is Spring Security in Spring Boot 4 and what are the key Boot 4 changes?

Spring Boot 4 ships with Spring Security 7, which introduces multi-factor authentication (MFA) and important changes to default security configurations -- particularly CSRF protection defaults that can silently break REST APIs.

// Spring Boot 4 / Spring Security 7: SecurityFilterChain
@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            // REST APIs: disable CSRF (Spring Security 7 default changed!)
            // Boot 3: CSRF enabled by default; REST APIs often disabled it
            // Boot 4 / Security 7: review CSRF defaults -- new SameSite-based protection
            .csrf(csrf -> csrf
                .csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
            )
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/actuator/health", "/api/public/**").permitAll()
                .requestMatchers("/api/admin/**").hasRole("ADMIN")
                .anyRequest().authenticated()
            )
            .sessionManagement(session -> session
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)  // for JWT/OAuth2
            )
            .oauth2ResourceServer(oauth2 -> oauth2
                .jwt(jwt -> jwt
                    .decoder(JwtDecoders.fromIssuerLocation(issuerUri))
                )
            );
        return http.build();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}

// Spring Security 7: Multi-Factor Authentication
// MFA is now a first-class concept in the security model
// Configure in SecurityFilterChain with mfa() DSL
// Previously required custom implementations

Key Spring Security 7 change for Boot 4: Spring Security 7 changes some CSRF and session management defaults. Teams migrating from Boot 3 should review their SecurityFilterChain configurations carefully -- previously-passing REST API tests may fail if CSRF defaults behave differently.

What notable feature does Spring Security 7 (included in Spring Boot 4) introduce as a first-class concept?
Why might a REST API's integration tests start failing after upgrading to Spring Boot 4 / Spring Security 7?

More Related questions...

What is Spring Boot 4 and when was it released? What is the complete modularisation of Spring Boot 4 and why does it matter? What is the Java version baseline in Spring Boot 4 and what Java features does it unlock? What is Jakarta EE 11 and what changes does it bring in Spring Boot 4? How does Spring Boot 4 auto-configuration work and what is the new @AutoConfiguration annotation? What is native API versioning in Spring Boot 4 and how do you use it? What are JSpecify nullability annotations in Spring Boot 4 and why are they important? What changed with Jackson in Spring Boot 4 and what are the migration considerations? What are @Retryable and @ConcurrencyLimit in Spring Boot 4 and how do they work? What are HTTP Service Clients in Spring Boot 4 and how do you define them? What are the key breaking changes removed in Spring Boot 4 that were deprecated in Boot 3? How does Spring Boot 4 handle dependency injection and what are the core stereotypes? What is Spring Boot's application.properties / application.yml and how does configuration work? What are Spring Boot profiles and how do you use them for environment-specific configuration? How does Spring Boot 4 testing work with @SpringBootTest and test slices? What is Spring Boot Actuator and what does it provide in Boot 4? How does Spring Boot 4 handle data access with Spring Data JPA? What is Spring Security in Spring Boot 4 and what are the key Boot 4 changes? What is the Spring Boot starter parent (POM) and how do you set up a Spring Boot 4 project? What is @SpringBootApplication and what does it combine? How do you build REST APIs with Spring Boot 4 using @RestController? How does Bean Validation work with Spring Boot 4? What is Spring Boot's embedded server and how do you configure it? What is Spring Boot's transaction management with @Transactional? What is Spring Boot's caching abstraction and how do you use it? What is Spring Boot's observability stack in Boot 4 with Micrometer and OpenTelemetry? How does Spring Boot 4 support GraalVM native images? What is Spring WebFlux and reactive programming in Spring Boot 4? What is Spring Boot's exception handling with @RestControllerAdvice? How do you use Spring Data MongoDB and other NoSQL stores in Spring Boot 4? How does Spring Boot 4 handle async processing with @Async? What is Spring Boot's externalized configuration with @Value and @ConfigurationProperties? What is Spring Boot's messaging support with Kafka in Boot 4? How do you schedule tasks in Spring Boot 4 with @Scheduled? What is Spring AI and how does it integrate with Spring Boot 4? How does Spring Boot 4 handle logging configuration? What is Spring Boot 4 migration from Boot 3: complete checklist and common pitfalls? What is Spring Boot DevTools and how does it improve development productivity? How does Spring Boot 4 support containerised deployments with Docker? What is the Spring Boot 4 vs Spring Boot 3 comparison and what are the key takeaways?
Show more question and Answers...


Comments & Discussions