Spring Core - Learn Spring Framework 4 And Spring Boot, Banshee S01E02 HDTV x264-EVOLVE[ettv]Banshee S01E02 HDTV x264-EVOLVE[ettv]
9e6c80dfbb Theres a whole chapter that talks about this and some of your options to get up and going. But Spring doesnt automatically add that token tag to every single HTML form in your application. This is fairly basic, understandable, and only takes a couple dozen lines of code even in a verbose language like Java. There are still some odd quirks here and there in Boot, and in general I would recommend that people stay one minor version behind so that others can work out the new-release kinks. Greg Turnquist Steve, Learning Spring Boot is now available for pre-order at We are doing the final edits and it should be shipping in less than two weeks. Security is very difficult to get right and it is unlikely any individual will get it right on their own. I backed off on my plans for my application, and will only be supporting local authentication for now. It brings you up to speed quickly, but all the magic done in the back severely bite you in the back when you need different behavior. I thought it would all be single page apps & html, but now Ive got to look at Thymeleaf : ) Steve Perkins Wellllllllllll& I dont know.
Surprisingly, once I worked out all the Maven dependencies and classpath issues, there were virtually no code changes necessary& *except* in the Spring Security portions. The more feedback we get from the community (both good & bad) the better the project can become. I was once on a project that attempted to marry Java-configured Spring MVC with XML-configured Spring Security, and it was a very bad experience until we eventually gave up and reverted to XML-config throughout. Im going to do my best to respond your comments as concisely as possible. Please click here if you are not redirected within a few seconds. It never worked&.Ended up being less work to implement it all from scratch. For example, the guice dependency you mentioned is not ideal in a Spring environment. I do agree Spring Security has been a bit behind on things. How do you compare the BCrypt hash for encoded passwords? Do you use expectedHash.equals(actualHash)? How many engineers would do this? If so, you are exposed to timing attacks. The Spring Boot Security starter doesnt include the OpenID pieces This is true, but the starter shouldnt pull in every dependency that Spring Security has.
Giranhla replied
473 weeks ago