spring-security-configurator-auditor

작성자: kotlin

Kotlin 및 Spring 서비스를 위한 Spring Security 구성 설계 및 감사, 필터 체인, JWT 또는 OAuth2 리소스 서버 설정, 메서드 보안 등을 포함합니다.

npx skills add https://github.com/kotlin/kotlin-backend-agent-skills --skill spring-security-configurator-auditor

Spring Security Configurator Auditor

Source mapping: Tier 2 high-value skill derived from Kotlin_Spring_Developer_Pipeline.md (SK-13).

Mission

Produce a security model that is explicit, minimal, and testable. Optimize for least privilege and correct failure semantics, not for shortest config.

Read First

  • Current SecurityFilterChain or chains.
  • Endpoint inventory, including actuator, docs, and internal admin routes.
  • Authentication model: session, JWT, OAuth2 resource server, API keys, mTLS, or mixed.
  • Authorization model: roles, scopes, claims, method security, tenant boundaries.
  • CORS, CSRF, and security-related tests.

Design Sequence

  1. Define who the clients are: browser, internal service, public API consumer, job, or operator.
  2. Define authentication mechanism and token trust boundaries.
  3. Enumerate public endpoints explicitly.
  4. Define authorization at URL and method level.
  5. Define 401 and 403 behavior.
  6. Add tests for the critical allowed and denied paths.

Core Security Rules

  • Prefer explicit allowlists for public endpoints.
  • Validate JWT issuer, audience, expiration, signature, and clock-skew assumptions deliberately.
  • Map claims to authorities with a documented rule. Do not assume the default claim mapping is correct for the identity provider.
  • Keep method security and request security aligned. One should not silently compensate for the other.
  • Treat CORS as a policy surface, not a browser nuisance.

Advanced Security Traps

  • Multiple filter chains are ordered. A broad matcher in the wrong chain can shadow a more specific secure chain.
  • permitAll for docs or actuator endpoints often expands further than intended when matchers are too broad.
  • CSRF is not automatically irrelevant just because the app uses tokens somewhere. Browser-based flows and cookie-backed auth change the answer.
  • Async execution, schedulers, and message listeners may not carry the same security context as request threads.
  • Method security on internal helper methods does not help if the call never crosses the proxy boundary.
  • JWT validation without issuer or audience checks is weaker than many teams realize.
  • CORS preflight failures can look like auth failures even when the backend logic is correct.
  • Security behavior differs between servlet and reactive stacks; do not transplant config blindly.

Advanced AuthZ And Token Nuances

  • Path-based authorization is often necessary but rarely sufficient. Tenant, ownership, or resource-state checks may belong in method or domain-level authorization.
  • JWT key rotation, JWKS caching, and clock skew policy are operational concerns as well as security concerns. Token validation must keep working during key rollover.
  • Opaque token introspection, JWT validation, and gateway-terminated auth have different failure modes and trust boundaries. Be explicit about which layer owns what.
  • Custom claim mapping can accidentally drop scopes or elevate privileges if the mapping rule is too permissive.
  • Security headers, session creation policy, and stateless assumptions should match the actual client model rather than copied boilerplate.

Expert Heuristics

  • Model "who can do what to which resource under which tenant or context" before writing matcher code.
  • Prefer deny-by-default designs where new endpoints start closed unless explicitly opened.
  • If browser and machine clients coexist, treat them as separate security surfaces even inside one service.
  • If an endpoint is operationally sensitive but "internal," still secure it explicitly. Internal does not mean safe.

Output Contract

Return these sections:

  • Threat surface: what must be protected and from whom.
  • Authentication model: how identity is established and verified.
  • Authorization model: how access decisions are made.
  • Critical findings or risks: insecure defaults, over-broad rules, missing checks, missing tests.
  • Minimal secure config plan: the smallest safe configuration or patch.
  • Verification: security tests for both allowed and denied access.

Guardrails

  • Do not disable CSRF or frame options without explaining the trust model.
  • Do not rely on default matcher behavior without checking path coverage.
  • Do not leave actuator, Swagger, or internal diagnostics exposed by convenience.
  • Do not generate security config without tests for the key routes.
  • Do not conflate authentication failure with authorization failure.

Quality Bar

A good run of this skill makes the access model explicit and auditable. A bad run produces a working login flow while leaving route exposure, token validation, or test coverage dangerously vague.

kotlin의 다른 스킬

kotlin-backend-jpa-entity-mapping
kotlin
Kotlin의 data class는 DTO에 자연스럽지만 JPA 엔티티에는 위험합니다. Hibernate는 data class가 깨뜨리는 identity 의미론에 의존합니다. 모든 필드에 대한 equals/hashCode는 상태 변경 후 Set/Map 멤버십을 손상시키고, 자동 생성된 copy()는 관리되는 엔티티의 분리된 복제본을 만듭니다.
kotlin-tooling-agp9-migration
kotlin
Android Gradle Plugin 9.0은 동일한 모듈에서 Android 애플리케이션 및 라이브러리 플러그인을 Kotlin Multiplatform 플러그인과 호환되지 않게 만듭니다. 이 스킬은 마이그레이션 과정을 안내합니다.
kotlin-tooling-cocoapods-spm-migration
kotlin
KMP 프로젝트를 CocoaPods(kotlin("native.cocoapods"))에서 Swift Package Manager(swiftPMDependencies DSL)로 마이그레이션 — pod()를 swiftPackage()로 대체,…
kotlin-tooling-immutable-collections-0-5-x-migration
kotlin
Kotlin(및 Java) 코드를 kotlinx.collections.immutable 0.3.x / 0.4.x에서 최신 0.5.x로 마이그레이션합니다. 0.5.x 라인은 모든 복사본을 반환하는 메서드의 이름을 변경합니다…
kotlin-tooling-java-to-kotlin
kotlin
Java 소스 파일을 체계적인 4단계 변환 방법론을 사용하여 관용적인 Kotlin으로 변환하며, 각 단계에서 5가지 불변 조건을 확인합니다. 애노테이션 사이트 대상, 라이브러리 관용구, API 보존을 처리하는 프레임워크 인식 변환을 지원합니다.
kotlin-tooling-native-build-performance
kotlin
Kotlin Multiplatform 프로젝트에서 iOS를 대상으로 할 때 느린 Kotlin/Native 컴파일 및 링크를 진단하고 수정합니다. 사용자가 느린 iOS 또는…을 보고할 때 사용하세요.
kotlin-spring-proxy-compatibility
kotlin
Diagnose and prevent Kotlin plus Spring proxy failures around `@Transactional`, `@Cacheable`, `@Async`, method security, retry, configuration proxies, and JPA…
ci-cd-containerization-advisor
kotlin
재현 가능한 빌드, 이미지 및 배포 파이프라인을 설계합니다. Kotlin 및 Spring 애플리케이션을 대상으로 하며, CI 검증, 계층형 컨테이너, 롤아웃 안전성 등을 포함합니다.