A request hits a Spring Boot 3 app with Spring Security. Describe what happens before the controller runs.
basicThe servlet container passes the request to DelegatingFilterProxy/FilterChainProxy (the bean named springSecurityFilterChain), which selects the first SecurityFilterChain whose securityMatcher matches and runs its filters in order. Only if all pass does the request reach DispatcherServlet.
- Typical order:
SecurityContextHolderFilter,HeaderWriterFilter,CorsFilter,CsrfFilter,LogoutFilter, authentication filters (UsernamePasswordAuthenticationFilter,BearerTokenAuthenticationFilter),AnonymousAuthenticationFilter,ExceptionTranslationFilter,AuthorizationFilter. - Debug with
logging.level.org.springframework.security=DEBUGor@EnableWebSecurity(debug = true)(dev only).
- Do multiple
SecurityFilterChainbeans all apply? No, only the first matching one (by@Order) handles a request. - Where does
ExceptionTranslationFiltersit and why? Just before authorization, so it convertsAccessDeniedException(401 entry point or 403) into HTTP responses.