Security
These guides show how to secure a Vaadin application with Spring Security: how users log in and out, and how to restrict what each user can see and do.
Read them in order. Add Login and Add Logout set up authentication. Protect Views controls which views each user can open, and what they can do in them. Protect Services enforces the same rules in the application services. Protect both: the views decide what users can reach through the user interface, and the services are the actual security boundary.
Add Login uses an in-memory user store, which you should only use for development and testing. To let users log in with an existing account at an identity provider, see OAuth2 Authentication.
To verify the security rules with automated tests, see Test View Access Control and Testing Method Security.
Topics
- Add Login
- Learn how to add user login to a Vaadin application using Spring Security.
- Add Logout
- Learn how to securely logout users from a Vaadin application using Spring Security.
- Protect Views
- Learn how to protect views in a Vaadin application based on user roles.
- Protect Services
- Learn how to protect services in a Vaadin application based on user roles.