November 2017
Intermediate to advanced
542 pages
14h 24m
English
We have already discussed how Spring Security uses SecurityContextHolder to determine the currently logged in user. However, we have not explained how SecurityContextHolder gets automatically populated by Spring Security. The secret to this lies in the o.s.s.web.context.SecurityContextPersistenceFilter filter and the o.s.s.web.context.SecurityContextRepository interface. Let's take a look at the following diagram:

Here is an explanation for each step shown in the preceding diagram:
Read now
Unlock full access