1
0
Files
spring-security-demo/README.md
asmhatre 5e9e7f1b12 Split into per-article modules and add the method-security module
Moves the existing virtual-thread/context-propagation project into
context-propagation/ and adds method-security/ for the Spring Security 7
method-security article: nine runnable demos, fourteen assertions, and every
transcript the article quotes, regenerated by scripts/run-all.sh.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RSrsDSRKVsY588yFiMJMo9
2026-08-25 02:01:29 +00:00

2.1 KiB

spring-security-demo

Companion code for the Spring Security series on ankurm.com. Each directory is a self-contained Maven project for one article, with its own pom.xml, its own numbered documentation chapters, and its own captured output under docs/output/ — regenerated by that module's scripts/run-all.sh, never typed by hand.

Module Article What it demonstrates
context-propagation/ Spring Security Context Propagation: The Complete Guide Whether a SecurityContext survives @Async, executors, virtual threads, StructuredTaskScope, Reactor, schedulers and the servlet filter chain
method-security/ Method Security in Spring Security 7: @PreAuthorize, @PostAuthorize and the Proxy Traps What the method-security annotations do, the full SpEL surface, and the cases where the check silently does not run

The two are related more closely than they look. Method security reads the Authentication from SecurityContextHolder on the calling thread; the context-propagation module is about getting it there. An @Async method carrying @PreAuthorize fails with AuthenticationCredentialsNotFoundException for reasons that belong to the first module, not the second.

Common ground

Both modules target the same verified stack: JDK 25 (Temurin 25.0.4.1+1), Spring Framework 7.0.9, Spring Security 7.1.1 — the versions Spring Boot 4.1.1 manages. Versions were taken from maven-metadata.xml on Maven Central rather than from release announcements.

context-propagation additionally needs --enable-preview, because StructuredTaskScope is still a preview API on JDK 25. method-security does not.

Running either module

cd method-security          # or context-propagation
./scripts/run-all.sh        # every demo plus the test suite, regenerating docs/output/
mvn test                    # just the assertions

License

MIT — see LICENSE.