springboot-security

Installation
SKILL.md

Spring Boot Security Review

Use when adding auth, handling input, creating endpoints, or dealing with secrets.

Authentication

  • Prefer stateless JWT or opaque tokens with revocation list
  • Use httpOnly, Secure, SameSite=Strict cookies for sessions
  • Validate tokens with OncePerRequestFilter or resource server
@Component
public class JwtAuthFilter extends OncePerRequestFilter {
  private final JwtService jwtService;

  public JwtAuthFilter(JwtService jwtService) {
    this.jwtService = jwtService;
  }
Installs
5
GitHub Stars
3
First Seen
Feb 27, 2026
springboot-security — oldwinter/skills