Security filters, JWT and domain authorization
Prerequisites: 01-ecosystem
Where does identity become resource access?
Goal & mental model verified
SecurityFilterChain applies authentication and authorization to matching servlet requests. A resource server verifies bearer tokens and derives authorities; accepting a decoded token is not equivalent to verifying it.
[S32] [S33]Worked example · design exercise synthesis
With Keycloak as issuer, validate the JWT signature, issuer and applicable claims. Convert claims deliberately, then check that the authenticated agent may access the requested tenant’s policy.
[S32] [S33]Engineering decision synthesis
Keep identity-provider responsibilities separate from application resource rules. Token authorities can express permissions, but row/tenant ownership still belongs in enforceable application logic.
[S32] [S33]Pitfall & diagnosis synthesis
A valid token can target another tenant’s resource. Incorrect matcher order can leave a route under the wrong filter chain. Configure audience requirements rather than assuming they are always enforced automatically.
[S32] [S33]Improve & validate synthesis
Test anonymous, expired, wrong-issuer, wrong-audience and cross-tenant requests. Inspect granted authorities and deny access consistently at the relevant resource boundary.
[S32] [S33]Check yourself: Does a valid JWT authorize every policy ID?
No. The application must enforce permission and ownership for that resource.