Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In this historical Spring 3.1 example, Spring Security protects REST endpoints by placing its filter chain before Spring MVC, requiring ROLE_ADMIN for /api/admin/**, and returning HTTP 401 rather than redirecting unauthenticated clients to an HTML login page. Form login can also be configured to return HTTP 200 after successful authentication instead of redirecting.

The example is specifically a form-login and cookie-session pattern using Spring Security 3.1-era XML configuration. It is useful for understanding the request flow, but its in-memory users and old dependency versions are not production or current-version recommendations.

How the Spring Security filter protects a REST endpoint

Spring Security is inserted into the web request path through a servlet filter. The filter delegates to the Spring bean named springSecurityFilterChain; that chain evaluates a request before Spring MVC handles it. The filter name must match the default bean name.

<filter>
  <filter-name>springSecurityFilterChain</filter-name>
  <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
</filter>
<filter-mapping>
  <filter-name>springSecurityFilterChain</filter-name>
  <url-pattern>/*</url-pattern>
</filter-mapping>

The /* mapping sends requests through the security filter broadly, not only requests under /api/*. That allows the application to protect other URL mappings as well. The security rule in the tutorial specifically requires the administrator role for /api/admin/**.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set authorization rules and the REST authentication entry point

The Spring Security namespace configuration groups the protected URL rule, authentication entry point, login behavior, logout, and authentication manager. The essential authorization rule is <intercept-url pattern="/api/admin/**" access="ROLE_ADMIN"/>. Requests matching that path require an authenticated principal with the administrator role.

For an unauthenticated request to a protected resource, a browser-oriented application commonly redirects to a login page. A REST client generally needs an HTTP status it can interpret, not an HTML redirect. The tutorial’s custom RestAuthenticationEntryPoint implements that behavior by sending an error from its commence method:

response.sendError(HttpServletResponse.SC_UNAUTHORIZED, "Unauthorized");

This makes the response status HTTP 401. It does not itself authenticate the caller or grant access; it defines how the application responds when authentication is needed and the request has not supplied valid credentials.

Make form login return 200 instead of redirecting

The example explicitly configures form login. Spring Security’s usual successful form-login flow redirects, which is useful for a browser navigating between pages but awkward for a REST client expecting a response. The tutorial uses a custom success handler based on SavedRequestAwareAuthenticationSuccessHandler with the redirect behavior removed, allowing a successful login response to return HTTP 200.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The security namespace setup may use <form-login>, as shown in the Java Code Geeks republication, or a custom filter positioned at FORM_LOGIN_FILTER, as described in the DZone version. Both belong to the historical configuration discussed here; they are not interchangeable with modern Spring Security configuration without version-specific adaptation. The configuration also includes <logout/>.

Understand the example’s users and client cookie flow

The sample authentication manager uses an in-memory <user-service> with example administrator and ordinary-user roles. It demonstrates role checks and a login flow, not a production identity store or a recommendation for managing real credentials.

In the republished example, the client posts credentials to /j_spring_security_check using j_username and j_password, retains the returned session cookie, then sends that cookie with a GET request to /api/foos and an Accept:application/json header. The illustrated successful resource response is HTTP/1.1 200 OK with a JSON array. These endpoint names and parameters are historical details tied to that tutorial configuration, not universal Spring Security login conventions.

Why Maven may select an older Spring dependency

The tutorial adds spring-security-web and spring-security-config, along with spring-tx and spring-aop. Its version problem arises because Spring Security artifacts can bring transitive Spring 3.0.x dependencies. Maven’s nearest-dependency conflict resolution may then select a transitive version such as 3.0.6 rather than the intended Spring 3.1.0.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The historical remedy is to declare the intended Spring dependencies directly in the application POM so they take precedence in dependency mediation. Check the resolved dependency tree when investigating a mismatch; adding Spring Security does not guarantee that Maven selects the Spring version you intended.

The source versions are historical examples, not current recommendations. The DZone copy gives spring-security.version as 3.2.2.RELEASE and spring.version as 3.1.3.RELEASE, while also discussing older snapshot versions. Those values should be read in their original historical context, not copied into a new application’s build without checking compatibility and support.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this approach does—and does not—cover

This tutorial’s scope is a stateful, cookie-oriented form-login flow configured with the Spring Security XML namespace. It does not demonstrate HTTP Basic, token authentication, or stateless request security. Nor does it provide a modern Java configuration example. The durable ideas are to put the security filter chain before request handling, define URL access rules, and deliberately choose the response behavior for unauthenticated and successfully authenticated REST requests.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.