Part 17 · Applications

Security filters, JWT and domain authorization

Prerequisites: 01-ecosystem

Where does identity become resource access?

HTTP request: bearer token; SecurityFilterChain: verify + authenticate; Authorities: mapped claims; Resource decision: permission + tenant. Connections: HTTP request to SecurityFilterChain (matched chain); SecurityFilterChain to Authorities (authenticated identity); Authorities to Resource decision (authorize use case)
Servlet resource-server example. Token verification and per-resource authorization are separate decisions. [S32] [S33]

Goal & mental model verified

SecurityFilterChain applies authentication and authorization to matching servlet requests. A resource server verifies bearer tokens and derives authorities; accepting a decoded token is not equivalent to verifying it.

[S32] [S33]

Worked example · design exercise synthesis

With Keycloak as issuer, validate the JWT signature, issuer and applicable claims. Convert claims deliberately, then check that the authenticated agent may access the requested tenant’s policy.

[S32] [S33]

Engineering decision synthesis

Keep identity-provider responsibilities separate from application resource rules. Token authorities can express permissions, but row/tenant ownership still belongs in enforceable application logic.

[S32] [S33]

Pitfall & diagnosis synthesis

A valid token can target another tenant’s resource. Incorrect matcher order can leave a route under the wrong filter chain. Configure audience requirements rather than assuming they are always enforced automatically.

[S32] [S33]

Improve & validate synthesis

Test anonymous, expired, wrong-issuer, wrong-audience and cross-tenant requests. Inspect granted authorities and deny access consistently at the relevant resource boundary.

[S32] [S33]
Keep this: Authentication names the caller; authorization constrains the action.
Check yourself: Does a valid JWT authorize every policy ID?

No. The application must enforce permission and ownership for that resource.

Sources & further reading

  1. [S32] Security servlet architecture

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: FilterChainProxy; SecurityFilterChain; Authentication and authorization

    Read the linked section to validate the mechanism and its version-specific constraints.

  2. [S33] JWT resource server

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: JWT verification; Issuer validation; Claim-to-authority conversion

    Read the linked section to validate the mechanism and its version-specific constraints.