Login and Sessions

View saved

Goal

This snapshot advances Ironclad Gazette by teaching you to authenticate with Spring Security form login.

Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.

Prerequisites

Use Java 17+, Maven, a terminal, and Docker for MySQL stages. You should recognize classes, annotations, and HTTP verbs.

Port 8080 must be free. Copy .env.example before starting database stages.

  • Java 17 and Maven
  • A code editor and terminal
  • Docker from part 4 onward

Concepts

Spring Security stores an opaque session cookie after form login. UserDetailsService loads the account by email on each request.

Keep controllers thin: accept input, delegate to repositories or services, and let Thymeleaf escape output by default.

Walkthrough

Configure form login, protect authenticated routes, and permit public pages.

Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.

http.formLogin(form -> form.loginPage("/login")
  .defaultSuccessUrl("/", true));

Run and verify

Enter 07-Login-And-Sessions, start MySQL when needed, copy .env.example, and run mvn spring-boot:run on port 8080.

Open http://127.0.0.1:8080. Watch the terminal for validation and database errors.

docker compose -f ../docker-compose.yml up -d
git clone https://github.com/michaeldunga1/fcc-spring-blog.git
cd fcc-spring-blog/07-Login-And-Sessions
cp .env.example .env
mvn spring-boot:run

Troubleshooting

Use email on the login form—Spring Security's username field maps to [email protected].

Connection refused usually means Docker MySQL is stopped or the port is not 3308. For auth issues, confirm you are using email (not username) on the login form.

  • Read the first error first
  • Restart after environment changes
  • Never commit .env or uploads

Try this

Log in, restart the app, confirm the session persists, then log out.

Test a happy path and one invalid or unauthorized request.

  • Make one small change
  • Test it in the browser
  • Compare with the next snapshot only after it works

Next: Profiles and Media

Comments

One comment per signed-in account. Comments are saved with this page’s URL.