Security filters apply authentication and authorization before controller work. Match rules deliberately and verify both permitted and rejected requests.
Before you start
You should know Java classes, dependency injection and basic HTTP requests. Identify where a call crosses a framework-managed boundary. The snippets illustrate a focused mechanism; database configuration, application wiring and authentication must be supplied by the surrounding application when applicable.
The practical goal is to reason through this situation: A public health endpoint and protected account endpoint need separate explicit policies. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Write the endpoint policy
Distinguish public health routes from protected account and administrative operations.
Step 2: Review matcher order
Broad permissive rules can unintentionally catch requests meant for stricter rules.
Step 3: Test negative authorization
Cover unauthenticated and authenticated-but-unauthorized requests, not only success.
Worked scenario
A public health endpoint and protected account endpoint need separate explicit policies.
A public health matcher must not accidentally permit every route under a broad prefix containing sensitive operations. Test HTTP methods and alternate URL spellings as well as the normal path. Authentication establishes identity; the administrative operation still needs an authorization decision.
Common mistake
A broad permit-all matcher can accidentally override intended protection.
Verify the behavior
Exercise each role and relevant method through the actual filter chain.
Interview exercise
Test endpoint security.
Answer and reasoning
Cover unauthenticated, authenticated unauthorized and authorized users, including methods and alternate URL patterns.
Continue learning
Compare the scenario with the Spring Boot interview questions and test your understanding with the Spring Boot MCQs. For terminology and implementation details, consult the reference material.