
This lecture demonstrates a real world full stack Spring Boot and Angular app, featuring secure login, email verification, password reset, two-factor authentication, and user role management for customers and invoices.
Outline the two-part architecture of a Spring Boot backend and an Angular frontend. Explain data flow over http, layered components, and dockerized deployment with MySQL and RDS.
Identify and set up the Java development environment with the JDK, Spring framework and Spring Boot basics, and configure MySQL or Postgres for a back-end API using IntelliJ.
Experience a video-based, advanced full-stack course with Spring Boot and Angular, where concepts precede coding, questions are answered within 24 hours, and you receive backend and frontend source code.
Use start.spring.io to bootstrap a spring boot application with maven, add web, mysql driver, spring security, jpa, jdbc, lombok, and validation dependencies, generate, unzip, and open in IntelliJ to continue.
Review dependencies in pom.xml, convert the config to yaml, set up a local MySQL data source with Hibernate dialect and ddl auto, then run the app to validate user login.
Learn data modeling by outlining the four steps: understand requirements, conceptual model, logical model, and physical model, and tailor the physical model to databases like MySQL or Postgres.
Explore the conceptual model by identifying entities and their relationships with a simple visual, using entity-relationship diagrams or UML. Use free online tools like draw.io (diagrams.net) to create the design.
Translate business requirements into a secure, role-based full-stack design, focusing on user management (unique emails, jwt login, 2fa) and later customers, invoices, and search.
Explore the conceptual model for a user and role, using an entity diagram to show a 1 to 1 relationship and permissions, guiding business-friendly data modeling.
Define attribute data types in the logical model, using strings for names and roles and a date-time for user role assignments; establish a 1-to-1 user-role relationship.
Tailor the physical model to a database system by translating the logical model into SQL and performing reverse-engineering with MySQL Workbench to define users, roles, and user_roles and their relationships.
Explore foreign keys in the user_roles table and set on update and on delete rules—cascade, no action (restrict), or set to null—ensuring data integrity, with primary keys never updated.
Turn a complete physical data model into a MySQL database by forward engineering, generating SQL for tables and relationships, and validating results in MySQL Workbench.
Learn to transform a complete physical data model into a practical MySQL database using forward engineering in MySQL Workbench, generating SQL code for tables and relationships.
Explore when to use JDBC and SQL alongside JPA and Hibernate in a Spring Boot API, balancing object-relational mapping with direct queries to handle complex data.
Learn SQL naming conventions for a Spring Boot API: use underscores, plural table names, and spell out id fields as item_id, with clear foreign key naming.
Design a secure schema and implement a comprehensive users table with id, name, email, credentials, profile fields, MFA flag, and a unique email constraint; prepare relationships to related tables.
Design and implement a roles system with a roles table and a user_roles join, enforcing unique role names, comma-delimited permissions, and cascade updates to maintain a secure user role relationship.
Design a two-table events and user_event model to capture IP address, device, date, and type, with foreign keys and a check constraint listing types like login attempt and profile update.
Create an account_verifications table to store the user id and verification url with unique constraints. Optionally include an expiration date for the link and enable auditing of account creation.
Design and implement a reset password verification table with id, user_id, url, expiration_date set to 24 hours, and unique constraints on user_id and url, linking to the user table. Then implement two-factor authentication by adding a code field in a separate table for verification after login.
Implement two factor verification with a table using user_id as primary key, a unique code, and expiration. Include a foreign key to users and account lock to prevent brute force.
Run application schema by dropping existing tables, initializing the schema from the SQL file, and correcting time zone settings; then explore forward and reverse engineering of the data model.
Use reverse engineering in MySQL Workbench to create a physical model from your database, connecting and executing, then compare forward and reverse engineering and prepare for Java work.
Create a new user by defining domain and repository interfaces with CRUD operations, paging, and boolean delete results in a Java Spring Boot app.
Define a user class using Lombok, super builder, and json include, with field validations to mirror database schema and enable user creation in a Spring Boot API.
Implement the user repository using a named parameter JDBC template in Spring Boot, covering email uniqueness checks, user creation, role assignment, verification flow, and robust error handling.
Implement an email uniqueness check in the user repository by counting existing emails and throw an API exception when the count exceeds zero.
Save a new user, capture the generated id with a key holder, and assign a role via a role repository; move queries into a dedicated user query class.
Create a role repository aligned with the user repository and model a role domain with id, name, and permissions; add role to user via a role type enum.
Implement a get sql parameter source to map first name, last name, email, and password. Encode the password and generate a verification url via uuid and verification type enum account.
Implement the user verification flow by building a backend verification URL, persisting it in account_verification, and preparing to email the URL after saving the user and role.
Implement the user role repository by creating its concrete class and adding methods to get role by user id and by user email, and update the user role.
Implement the role to user feature in the user repository using JDBC template, a role mapper, and new queries, with logging and incremental testable steps.
Implement insert queries for users, account verifications, and user roles using named parameters, add role queries, and scaffold service and controller for testing user creation.
Create a user service using the dto pattern, expose a user dto without the password, and implement a dto mapper to transform between user and user dto in Spring.
Implement the user service to create users by wiring the repository and mapper to return a user dto, then expose a rest resource at /user/register with a custom http response.
Demonstrates creating a user via a Spring Boot API by validating the request body and returning a created status with the resource location.
populate the roles table with role user, role manager, role admin, and role sysadmin and their permissions to prevent failures during user creation.
Boost debugging and testing in a Spring Boot app by diagnosing a bcrypt encoder bean error, inspecting logs, and validating fixes with Postman; use profiles and security auto configuration.
Configure environment-specific properties for a Spring Boot app, switch between dev and prod via profiles, use Maven pom profiles, and enable seamless deployment via cd/ci pipelines.
Learn to customize the Spring Boot banner by adding a banner.txt in resources, set the application title and version in application.properties, and verify the banner appears after rerunning the app.
Discover how spring security uses filters to guard requests, routing through the authentication manager and providers, with token-based authentication and access and refresh tokens.
Create a security configuration package and define a security filter chain bean to configure http security, authentication providers, and notes on JSON web token and OAuth 2 with Spring Security.
Disable CSRF and set stateless session management for a JWT-based API, define public URLs with permit all, and enforce delete permissions via has authority.
Configure login security in part 3 by defining an authentication manager and provider, wiring a username-password authentication flow, and integrating a bcrypt password encoder with a user details service.
Remove the default access denied handler and authentication entry point to implement a custom user detail service and deliver a JSON error response with a Spring bean and object mapper.
Configure a custom authentication entry point and access denied handler in Spring Security, then implement a user detail service that loads user data and returns user details for authentication.
Upgrade to spring boot 3.0.0, update security configuration to http request and request matchers, enable method security with pre-post default true, and note upcoming jpa and spring data jpa changes.
Implement a custom user details service and user principal to let Spring Security authenticate users via load user by username, translating permissions into granted authorities.
Configure a custom user details service to load users by email for login, map roles and permissions to a user principal, and integrate with Spring Boot security.
Test the login flow by building a login form (email and password), authenticating with the authentication manager, and returning a user DTO on success; prepare for MFA checks.
Update the pom to the latest spring boot 3.22, refresh dependencies, and modernize the security filter chain with a lambda-based configuration, disabling csrf, enabling stateless sessions, and permitting public URLs.
Review architectural design focusing on resources, services, repositories and SQL, as we prepare to introduce an SMS API for MFA: sending a code, storing it, and verifying with two-factor authentication.
Introduce the Apache Commons Lang library via Maven, and implement sending verification codes for MFA, including 24-hour expiration, two-factor verification table storage, and SMS delivery.
Set up Twilio to send SMS verification codes in Java using Twilio SDK, including configuring account SID, auth token, from and to numbers, and creating an SMS utils class.
learn to implement a verification code flow with MFA in a full stack spring boot api with angular frontend, test login with postman, and plan access and refresh token issuance.
Review the login flow for non two-factor and two-factor scenarios, detailing how access and refresh JSON web tokens are issued after successful authentication and MFA code verification.
Learn how to implement a token provider using java jwt (auth0 by okta) to generate and sign access and refresh tokens from a secret and user authorities.
Implement access and refresh tokens with 30 minutes and five days expirations, and derive user authorities from token claims using a JWT verifier.
Implement getAuthentication to build a username password authentication token from the email, authorities, and request. Validate tokens with isTokenValid and isTokenExpired using a JWT verifier to obtain the subject.
Learn to implement token-based login with a token provider that creates access and refresh tokens, injects them into login responses, and uses user and role services to set permissions.
Verify code endpoint processes a get request to /verify/code with email and code, validates them via the repository and the two factor authentication table, and returns tokens.
Master the login flow with multifactor authentication, including verification code generation and validation, access and refresh token issuance, testing with console logs, and secure one-time code deletion for PostgreSQL.
Refactor the user flow by introducing a user dto and a dedicated mapper to map roles and permissions, centralizing mapping in the service for cleaner separation.
Demonstrates testing login after refactoring by validating MFA flow, two-factor codes, and role-based permissions, while refining error handling, validation, and separating business logic from controllers.
Implement an authorization filter to intercept requests and read the token from the authorization header. Validate token and set the authenticated user in the security context to access protected routes.
Create a custom authorization filter that runs once per request, extracting email and token, validating them with a token provider, and setting authentication in the security context.
Implement a token-based authorization filter by extracting a bearer token from the authorization header, validating it, and exposing protected routes while allowing public URLs and preflight options.
Bind the current request authentication with a Spring Security authorization filter, then expose profile data by email using the access token.
Build a robust exception handling utility for a full stack Spring Boot API with Angular, handling token and security errors and returning JSON responses with appropriate HTTP statuses.
Trigger and observe how the authorization filter throws errors for expired tokens and invalid claim exceptions, and implement global exception handling with a controller advice in Spring Boot API.
Learn advanced exception handling in a full stack spring boot api with angular by building a custom error controller, overriding handle exception internal and handle method argument not valid.
Explore advanced exception handling in Spring Boot by implementing controller advice, catching specific exceptions like SQL integrity constraint violation, customizing messages, logging with SLF4J, and returning meaningful bad request responses.
Demonstrates testing exception handling in a full-stack Spring Boot API with Angular, using Postman to validate empty fields, incorrect credentials, and locked accounts, and introducing an error controller.
Override the white label error page by implementing a custom error controller, configuring the error path, and returning a consistent bad request response for unknown routes.
Refactor the login flow to reduce two database calls and return the full authenticated user as a user DTO via the authentication manager, the security context, and the principal.
Run and test the app with postman, log authentication details, and inspect the user DTO from the authentication principal to verify access and refactoring outcomes.
Learn the not-logged-in reset password flow and contrast with the logged-in path: generate a key, email a URL, verify the key, and set a new password.
Implement a reset password flow by exposing a get mapping that accepts user email, verifies the user, generates a UUID URL, deletes tokens, stores with expiration, and sends an email.
Test and secure the reset password flow by whitelisting the endpoint and handling unauthenticated requests. Validate input and verify the email token and verification URL in the database.
implement verify password key flow to validate reset links, handle expiration, and return the user dto for front-end use, including queries to fetch users by reset url.
Run the reset password flow with Postman, verify the password reset and user verify password URLs, whitelist the endpoints, and fix a SQL syntax error to enable successful password updates.
Add a renew password endpoint that validates passwords, encodes the new password, updates the user by URL, and removes the reset verification record.
Test the reset password flow with a key, post a new password, ensure passwords match, log in with the new password, and confirm the reset link is deleted from database.
The Java Spring Framework (Spring Framework - Spring Boot) is a popular, open source, enterprise-level framework for creating standalone, production-grade applications that run on the Java Virtual Machine (JVM). Java Spring Boot (Spring Boot) is a tool that makes developing web application and micro-services with Spring Framework faster and easier through three core capabilities, mainly its auto-configuration An opinionated approach to configuration.
Spring Boot is an open source Java-based framework used to create a micro Services. It is developed by Pivotal Team and is used to build stand-alone and production ready spring applications. This course will give you an in-depth knowledge to Spring Boot and familiarize you with its advanced concepts. For practice, we will build a Spring Boot REST API that manages customers.
Angular is an open-source, JavaScript framework written in TypeScript. Google maintains it, and its primary purpose is to develop single-page web applications. As a framework, Angular has clear advantages while also providing a standard structure for developers to work with. It enables users to create large applications in a maintainable manner.
This course teaches how to build a full stack web application from the ground up and touches on very important concepts used in real-world software applications.