Moves the existing virtual-thread/context-propagation project into context-propagation/ and adds method-security/ for the Spring Security 7 method-security article: nine runnable demos, fourteen assertions, and every transcript the article quotes, regenerated by scripts/run-all.sh. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RSrsDSRKVsY588yFiMJMo9
2.1 KiB
spring-security-demo
Companion code for the Spring Security series on ankurm.com. Each
directory is a self-contained Maven project for one article, with its own pom.xml, its own
numbered documentation chapters, and its own captured output under docs/output/ — regenerated
by that module's scripts/run-all.sh, never typed by hand.
| Module | Article | What it demonstrates |
|---|---|---|
context-propagation/ |
Spring Security Context Propagation: The Complete Guide | Whether a SecurityContext survives @Async, executors, virtual threads, StructuredTaskScope, Reactor, schedulers and the servlet filter chain |
method-security/ |
Method Security in Spring Security 7: @PreAuthorize, @PostAuthorize and the Proxy Traps |
What the method-security annotations do, the full SpEL surface, and the cases where the check silently does not run |
The two are related more closely than they look. Method security reads the Authentication
from SecurityContextHolder on the calling thread; the context-propagation module is about
getting it there. An @Async method carrying @PreAuthorize fails with
AuthenticationCredentialsNotFoundException for reasons that belong to the first module, not
the second.
Common ground
Both modules target the same verified stack: JDK 25 (Temurin 25.0.4.1+1),
Spring Framework 7.0.9, Spring Security 7.1.1 — the versions Spring Boot 4.1.1
manages. Versions were taken from maven-metadata.xml on Maven Central rather than from
release announcements.
context-propagation additionally needs --enable-preview, because StructuredTaskScope is
still a preview API on JDK 25. method-security does not.
Running either module
cd method-security # or context-propagation
./scripts/run-all.sh # every demo plus the test suite, regenerating docs/output/
mvn test # just the assertions
License
MIT — see LICENSE.