Spring Security

Inter-company training

How long does the training course last?

 2,00 day(s)

In which language(s) is the training course taught?

EN FR

When will the next session take place?

Who is organising this training course?

Dawan is a training organisation that offers more than 2000 training courses in IT, management, project management and sales in instructor-led live online or on-site trainings. We have 11 centres in France and we have developed partnerships with local structures in Brussels, Luxembourg and Geneva. Our catalogue includes hundreds of topics: Java, PHP, Webmaster, E-Marketing, Linux, Windows Server, Vmware, Autocad, Photoshop, IA etc. Our courses have been created and designed by in-house trainers who have over 20 years of teaching experience. Constantly renewed, they are adapted to the requirements of our customers and to the evolution of technologies.

Who is the training course aimed at?

Développeurs Java EE

What are the prerequisites?

Maîtriser la programmation orientée objet en Java

What are the aims or the skills being targeted?

Construire des applications Java EE sécurisées avec Spring Security.

What does the training course cover?

Découvrir Spring Security

Aspects sécurité dans une application Java EE
Spring Security: présentation, fonctions
Architecture du framework
Dépendances, configuration(XML ou annotations)

Implémenter une authentification avec Spring Security

Mécanismes d'authentification (authenticationProvider):

  • utilisateurs en mémoire
  • liaison vers une base de données
  • liaison vers un annuaire LDAP

Pages de login/logout
Objets Spring: SecurityContext, Authentication

Configurer des rôles et gérer des autorisations

Implémentation de web filters:

  • principaux filtes
  • authentification Basic vs Digest
  • Implémentation d'un Remember Me
  • authentifications anonymes

Gestion des sessions: informations, concurrence
Gestion des autorisations:

  • sur des requêtes
  • sur des objets et des méthodes
  • par rôle et par type d’authentification
Se prémunir contre les attaques

Intégration avec l’API Servlet
Encodage des mots de passe
Localisation des messages
Taglib Spring Security
Injection dans un contexte de tests
Sécurisation des WebSockets
Gestion des attaques CSRF (Cross Site Request Forgery)
Configuration des en-têtes de réponse http: sécurité, cache

What teaching methods are used?

Méthodologie basée sur l'Active Learning : 75% de pratique minimum. Chaque point théorique est systématiquement suivi d'exemples et exercices.

How is the assessment organised?

Contrôle continu

What will you receive at the end of the training course?

Attestation de fin de stage mentionnant le résultat des acquis

What course materials are provided?

Support de cours + exercices

How to contact the training provider?

Dawan - Service commercial

These courses might interest you