Observed Signal · Jun 18, 2026 · Technical Release · Source: DEV Community · Impact: 4/5 · Sentiment: Positive
Spring Security 7 Released: Built-in MFA and Modular Config
Spring Security 7 was released at Spring I/O 2026 and delivers several major platform changes for Java apps on Spring Boot. The release adds first‑class Multi‑Factor Authentication (MFA) with APIs and authorities (e.g., FactorGrantedAuthority, @EnableMultiFactorAuthentication, AllRequiredFactorsAuthorizationManager) that support site‑wide, per‑endpoint and time‑based recency rules. Configuration becomes more modular: developers can supply Customizer<HttpSecurity> and targeted configurer customizers instead of replacing the Boot SecurityFilterChain defaults. Legacy APIs were removed (OAuth2 password grant, the .and() DSL) and module packages were reorganized. OAuth2 updates include PKCE enforced by default, a dynamic client‑registration endpoint (/oauth2/register) intended for MCP use cases, and OAuth2 token injection for Spring Framework 7 HTTP Service Clients. Spring AI provides MCP security starters, and Open Rewrite can automate many migration changes.
Major framework release from the Spring ecosystem introduces built-in MFA, modular config, and OAuth2 defaults (PKCE, removed password grant) that require migration but improve security and standardize auth flows across many Java applications.
Track Real-Time Identity Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Spring Security 7 was released at Spring I/O 2026.
- Built‑in MFA shipped with classes and annotations such as FactorGrantedAuthority, @EnableMultiFactorAuthentication, and AllRequiredFactorsAuthorizationManager.
- Configuration model is now modular: provide Customizer<HttpSecurity> or targeted configurer customizers instead of replacing Spring Boot defaults with a SecurityFilterChain bean.
- Removed legacy APIs: OAuth2 password grant and the chain-style .and() DSL; PKCE is enforced by default in the Authorization Server.
- OAuth2 additions: dynamic client registration endpoint (/oauth2/register) for one‑time client registration (MCP use), and automatic OAuth2 token injection for Spring Framework 7 HTTP Service Clients; Spring AI offers MCP security starters.
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Spring Boot IAM: OAuth2 Redirect Bug in Production
The author built identityCore, a self-hosted Identity & Access Management (IAM) service in Spring Boot, implementing form login plus Google (OIDC) and GitHub (OAuth2) logins, RBAC stored as JPA entities, and a unified provisioning flow. The post explains key differences between OAuth2 and OIDC (GitHub returns an opaque access_token requiring extra API calls; Google returns an id_token JWT), and describes a production-only bug where OAuth2 logins failed with redirect_uri_mismatch because TLS was terminated upstream and the app ignored X-Forwarded headers. The one-line fix was to set server.forward-headers-strategy=framework so Spring trusts proxy headers. The author lists operational lessons about protocol differences, deployment vs demo differences, and centralized user provisioning.
Google Authenticator Integration Guide for Spring Boot
A technical how-to showing step-by-step integration of Google Authenticator (TOTP) into a Spring Boot application. The guide covers required Maven dependencies, generating a per-user Base32 secret using SecureRandom, building an otpauth:// URI and QR code (using ZXing) encoded as a Base64 PNG for user setup, and verifying time-based one-time passwords on login. It also emphasizes secure storage of secrets, handling clock drift tolerance, and providing account recovery options. Originally published on the Innostax Engineering Blog and syndicated on dev.to.
How Spring Verifies RS256 JWTs Internally
A technical walkthrough explaining how Spring Security verifies RS256-signed JWTs between microservices. The article outlines configuration (jwk-set-uri in spring-boot), SecurityFilterChain setup with JwtAuthenticationConverter, and a protected endpoint that receives an injected Jwt. It then details BearerTokenAuthenticationFilter’s lifecycle: extracting the bearer token (DefaultBearerTokenResolver), wrapping it in a BearerTokenAuthenticationToken, delegating validation to AuthenticationManager → JwtAuthenticationProvider, and using NimbusJwtDecoder for RS256 signature, expiry and issuer checks. On success Spring populates SecurityContextHolder with an authenticated JwtAuthenticationToken; on failure it clears the context and triggers the AuthenticationEntryPoint to return 401 with WWW-Authenticate.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
