What You'll Learn
- Review OAuth and OpenID Connect concepts for social and enterprise applications
- Understand Keycloak as an Identity and Access Management provider
- Step-by-step use of Spring Security with Authorization Code Flow (with and without PKCE)
- Step-by-step use of Spring Security with Client Credentials Grant
- Build OAuth2 Clients, JWT, and Opaque Resource Servers using Spring Security
- Design enterprise authorization using Keycloak scopes and roles
- Hands-on integration with Okta SAML Identity Providers using Keycloak
- Hands-on Identity Brokering using Keycloak with OpenID Connect and GitLab
- Handle multiple Identity Providers in Spring Boot and Spring Security
This Course Includes
- 9.5 hours on-demand video
- Assignments
- 17 articles
- 8 downloadable resources
- Access on mobile and TV
- Certificate of completion
Course Content
10 sections • 98 lectures • 9h 59m total length
Section 1: Keycloak Setup and Introduction
- Architecture Diagrams — 3:49
- Keycloak Overview — 6:56
- Keycloak Installation and Setup — 7:41
- Postgres Installation and Setup — 4:57
- Keycloak Postgres Setup — 7:33
- Notes on Keycloak and Postgres Setup — 1:13
Section 2: OAuth and OpenID Connect Fundamentals
- Section Introduction — 1:28
- OAuth Actors — 8:58
- Clients and Scopes — 6:47
- Access Tokens and Endpoints — 6:45
- Authorization Code and Refresh Token Grants — 12:04
- Implicit Grant and PKCE — 7:16
- Client Credential and Password Grants — 3:35
- Third Party Versus First Party Application — 1:12
- OpenID Connect — 6:16
- Enterprise OpenID Connect and Roles — 5:43
- RFC Documentation Links — 0:37
Section 3: OAuth and OpenID Connect Project
- Introduction - Project BugTracker — 4:52
- BugTracker Demonstration — 6:15
- BugTracker Keycloak Setup — 9:04
- BugTracker Design — 4:01
- Spring Security - OAuth Authentication — 7:24
- BugTracker Service — 12:56
- BugTracker OpenID Connect Configuration — 9:45
- Spring Security - Authorized Client — 1:57
- BugTracker Controller — 15:03
- BugTracker with Authorization Code Grant — 10:59
- BugTracker with PKCE — 10:43
- BugTracker Authorization using Scopes — 16:07
Section 4: Authorization Using Roles
- JAUBS - Course Project Explanation — 16:05
- JAUBS - Protecting Application using OpenID Connect
- Solution for Assignment 1 — 18:47
- Keycloak Mapper - Adding Roles Claim — 3:45
- BugTracker Authorization using Roles — 7:54
- JAUBS - Protecting Application using Roles
- Solution for Assignment 2 — 6:45
Section 5: Multiple Identity Providers
- Handling Multiple Identity Providers — 3:48
- Client Registration in GitLab — 4:44
- Spring Security and Multiple Identity Providers — 8:06
- Customizing Authorities — 5:25
- Problems with Multiple Identity Providers — 4:32
Section 6: OAuth Microservices
- Creating an OAuth JWT Microservice (Resource Server) — 10:55
- Spring Security - Resource Server — 0:42
- Calling an OAuth Microservice — 8:44
- Using Introspection Endpoint — 9:32
- Enterprise Schedulers and Client Credentials Grant — 3:12
- Client Credentials in Keycloak — 5:10
- BugTracker Scheduler using Client Credentials — 9:00
Section 7: Identity Brokers
- Introduction to Identity Brokers — 6:46
- Identity Broker HTTP Message Flow — 4:35
- Setting up GitLab Identity Provider in Keycloak — 4:44
- BugTracker Identity Broker Integration — 7:26
- Setup Keycloak as Identity Broker for Google and GitLab
Section 8: SAML Integration
- SAML Overview — 5:26
- OpenID Connect and SAML Integration — 5:12
- BugTracker SAML Usecase — 3:41
- BugTracker SAML Integration with Okta — 19:11
- Creating an Okta Integrator Account — 0:52
- BugTracker Global Logout with Okta — 12:09
- SAML Identity Provider - Assertion Encryption — 7:33
- SAML Identity Provider - Setting User Attributes — 9:38
Section 9: OAuth and OpenID Connect Advanced Topics
- Handling Multiple Authorization Servers Simultaneously — 4:11
- Spring Security Configuration for OAuth — 11:14
- Accessing GitLab Resource Server — 2:45
- Spring Security - oauth2Login versus oauth2Client — 0:44
- Fixing the Login Page — 5:16
Section 10: Cryptography and Java Security Concepts
- Cryptography Theory and Practice — 0:29
- URL Encoding — 2:40
- Base64 Encoding — 2:15
- Cryptographic Hashing — 4:32
- Symmetric Encryption — 3:27
- Asymmetric Encryption — 7:25
- Hybrid Encryption — 4:34
- Digital Signatures — 5:13
- OpenSSL Demonstrations for Encryption and Signatures
- Enterprise Versus OAuth Authorization — 5:06
- OAuth Versus OpenID Connect (OIDC) — 10:11
- Java Nested Classes — 8:01
- Java Record - Model Immutable Data — 12:42
- Java ThreadLocals and Security Propagation
Requirements
- Basic working knowledge of OAuth
- Basic knowledge of Spring Boot
Description
Recent Updates:
- All Spring Boot examples tested and updated with Spring Boot 3.5.9
- Java 25
- Keycloak 26.5.0
Download
Password : free-udemy-course.en.gp
