
Build a full-stack user management app with Spring Boot and Angular, implementing login, sign up, user listing, and details, with JWT-based role-based authorization and MVC architecture.
Build a user management app with sign in and sign up, an admin dashboard, and authentication and authorization using jwt on spring boot backend and angular frontend.
Select Java 11 as the long-term support version and download it from Oracle. Install with default settings; the course supports minimum Java 11 and later versions.
Download and install IntelliJ, compare it to alternatives, and discover its faster learning curve, better code completion, with a free option versus a licensed version.
Install and configure Lombok in IntelliJ (pre 2021), and enable annotation processing to simplify server-side code by avoiding boilerplate getters and setters.
Search and download the MySQL Community Server for your OS, install it, and set up credentials while noting the version for future operations.
Download and install postman to test your APIs. Create API endpoints in your project and test them with postman using various request methods, then set authorization headers after registering.
Explore how Spring enables dependency injection through annotations, beans, and configuration, illustrating constructor, setter, and field injection with components, repositories, services, and controllers.
Explore rest controllers in spring boot and how http methods map to get, post, put, and patch operations, using request and response entities to control api endpoints and status.
Learn the basics of sql for relational databases, including creating databases and tables, defining columns and data types, using primary keys, and performing insert, delete, and select operations.
Explore how Lombok auto-generates getters, setters, equals and hashCode, and provides no-args and all-args constructors, enabling immutable classes.
Explore how the Spring @RequestParam annotation extracts query and form parameters from REST requests, customize parameter names, defaults, and required flags, and apply them in a sample API.
Explore the @PathVariable annotation in Spring to extract URI template variables, map them to method parameters, and control custom names with required or optional flags in a REST API.
Learn how the @RequestBody annotation maps the HTTP request body to a domain object and uses HTTP message converters, such as Jackson, to handle JSON or other content types.
Explore the three-layer server-side architecture—database, backend, and frontend—building user CRUD with Spring Boot, Spring MVC, Spring Security, and JWT, using MySQL, JPA, Hibernate, Lombok, and Maven.
Create a spring boot project with spring initializer, choose maven or gradle, java 11, set group and artifact, and add dependencies for security, jpa, data rest, and lombok.
Create a database user in MySQL Workbench, using localhost and the server users, then apply the changes; the next lesson will auto-create the database from configuration.
Configure and customize database properties for a Spring Boot project, including data source settings, UTC server time zone, create database if not exists, public key retrieval, and Hibernate auto settings.
Develop a user entity mapped to the users table, including id, username, password, name, and role, using JPA annotations and Lombok for accessors, for sign in and sign up.
Explore the four primary key generation strategies in JPA and Hibernate—default auto, identity, sequence, and table generators—through examples and tests. Learn how to choose the best option for your database.
Implement a user repository using Spring Data JPA's JpaRepository to enable basic crud operations, auto-generated queries, and custom queries with @Query and @Modifying for updates by username.
Develop a user service to handle business logic, interacting with repositories to save, find, update roles, and list users, with password encoding and transactional annotations.
Explore how authentication verifies user identities in spring security, focusing on basic authentication, authorization headers, and the role of authentication providers, manager, and security context.
Explore authorization architecture in spring security, where interceptors and access decision voters determine access to secured resources using permit all, deny all, fully authenticated, and remember me rules.
Learn how Spring Security handles authentication and authorization with default and custom configurations, including form login, basic header authentication, and cross-origin resource sharing. Explore CSRF protection and role-based access control.
Implement a custom user details service to load users by username, map roles to authorities, and build a user principal for Spring Security authentication using a builder pattern.
Configure security with WebSecurityConfigurerAdapter to set up the authentication manager and HttpSecurity for JWT authentication, enabling CORS, disabling CSRF, and permitting login and register.
Install and configure jwt libraries and jackson dependencies from maven, set a 512-bit secret key, choose rsa or hmac algorithm, and set a one-day expiration.
Generate and validate JWTs in a Spring Boot and Angular app, creating a JWT provider, extracting claims from HTTP requests, and enforcing token expiration via secure authentication.
Create and validate a custom JWT filter for SDP requests, set the authenticated user in the security context, and chain it before the username-password filter.
Explore how JWT infrastructure uses short-lived access tokens and long-lived refresh tokens, stored securely on the client, to renew access seamlessly.
Create a refresh token model class as a JPA entity linked to a user, with id, token, user id, created and expiration times, using Lombok for getters, setters, and equality.
Create a refresh token repository interface using JPA repository, enabling auto-generated queries like find by user ID and find by token ID, with default save and find by ID methods.
Implement refresh token service with two methods: create a refresh token for a user and generate an access token from a refresh token, using repositories and a JWT provider.
Implement the sign-in flow with the authentication manager and authentication service to validate username and password and issue a JWT access token and a refresh token.
Create a REST authentication controller to handle sign up, sign in, and refresh token requests by wiring the controller to the authentication, user, and refresh token services.
Implement a user controller to expose rest endpoints, call the user service for role changes, and secure requests with jwt authentication.
Implement an admin controller with rest endpoints under /api/admin. Inject the user service and secure admin routes so only a JWT admin token can fetch all users with Postman.
In this course, we will create a project like an user-management-system. When I say user-management-system, we can think of it like that we will have login, register pages and users can sign-in and sign-up from those pages then we can list all users and we can see the details of users.
And we will implement this project using Spring Boot, Angular, and MySQL.
In our project, we will implement CRUD operations. These CRUD operations will be for users. We will use users for user sign-in, sign-up and authorization operations.
These CRUD operations will be requested from Angular. So on the backend, we will create an infrastructure for these CRUD operations and on the frontend, we will serve them with the user interface.
Our project goes on with User operations.
Our main operations will be user login, register, user-list etc.
Also, we will go on with the role based application. So we will use different roles like “Admin”, “User”. User role will have typical operations like login, register.
But admin role will have some specific operations like to list all users. Then we will provide different authorizations to these users according to the role.
And this all things will be provided with a secure way in both Angular and Spring Boot.
We will have two main components to implement our project.
These are server side and client side.
In Server Side:
Of course here, our main library will be Spring-boot. We will implement the whole infrastructure on the backend with the Spring boot. It will provide easy and fast configuration to us.
We will implement the Model view controller architecture on our project.
Spring-security will be one of the main topics in our application. Also, we will use JWT to provide security. Also in the JWT part, we will see the differences between access-tokjen and refresh-token.
In Spring Boot, Data will be presented to the client as an API call so Spring Rest Controller will be used to handle it.
We will use MySQL as Database. Because most of us are familiar with it.
We will also use Object Relational Mapping with Java Persistence API and Hibernate.
You know, We can map our database tables to objects with hibernate.
We will use JPA Repository and Crud Repository in Spring Boot.
So these repository templates will handle common database operations like save, update, find, delete.
With Spring Boot, we will also use the Lombok library to clear code.
You know that we don't want to implement getter, setter, equals and hashcode. So we can escape it using Lombok @Data or @Value annotation.
We will use Maven To handle all dependencies on the server side. Actually, here we can also use Gradle. Gradle provides better performance than maven but Maven is the most common one. So we'll go on with maven.
That's all about Server side.
Let's talk about Client Side.
We will create an angular application on the client side and it will provide a cool user-interface. So we will create some pages like admin dashboard, login page and register-page. Then we will assign the server apis to these pages and we will consume and produce the data from the user-interface easily and user friendly.
On angular, we will also implement the model view controller architecture. We will use the cool features of typescript etc.
Last but not least, we will implement security and authorization on angular also. We will work with different roles and according to these roles, we will implement unauthorized and not-found pages on the user interface also.
We will see the details of them one by one.