Spring Security Configuration using XML
Spring Security can be configured either by using the XML or Java annotations. We have seen the Spring Security configuration with Java and annotations in the previous article. Now, we will learn to configure the application using XML. There is no difference if you use either java or XML both are good but in modern time, it is preferred to use Java-based configuration than XML.
Let's understand by the example. Create a maven-based spring application that will have the following source files.
Project Source Code
// UserController.java
This is our controller class that works as a user request handler and maps user requests with the resources and returns responses accordingly. We created home() method to show the index.jsp page and course() method to display course.jsp page.
package com.studytonight.controller;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.GetMapping;
public class UserController {
public String home() {
return "index";
public String course() {
return "course";
// application-context.xml
This file is used to configure view pages, components, and the controller class. It is similar to the AppConfig.java file of the Java configuration project.
<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans"
<!-- Step 3: Add support for component scanning -->
<context:component-scan base-package="com.studytonight.controller" />
<!-- Step 4: Add support for conversion, formatting and validation support -->
<!-- Step 5: Define Spring MVC view resolver -->
<property name="prefix" value="/WEB-INF/views/" />
<property name="suffix" value=".jsp" />
// spring-security.xml
This file is used to configure the users and their roles. In the user service tag, we set users' login credentials. This configuration is similar to the SecurityConfig.java file of the Java configuration project.
<?xml version="1.0" encoding="UTF-8"?>
<b:beans xmlns="http://www.springframework.org/schema/security"
xsi:schemaLocation="http://www.springframework.org/schema/beans https://www.springframework.org/schema/beans/spring-beans.xsd
http://www.springframework.org/schema/security https://www.springframework.org/schema/security/spring-security.xsd">
<intercept-url pattern="/" access="hasRole('GUEST')" />
<intercept-url pattern="/java-courses/**" access="hasAnyRole('GUEST', 'REGISTERED')" />
<user name="studytonight" password="{noop}abc123" authorities="ROLE_GUEST" />
<user name="pro-studytonight" password="{noop}abc123" authorities="ROLE_REGISTERED" />
// web.xml
It is used to configure the web application. Here, we set application-context.xml and spring-security.xml so that the application can find them during execution.
<?xml version="1.0" encoding="UTF-8"?>
<web-app version="3.0" xmlns="http://java.sun.com/xml/ns/javaee"
View Files
These are views files of our project that displayed to the browser. See the code.
// course.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
<!DOCTYPE html>
<meta charset="UTF-8">
<title>Course Page</title>
<h2>List of Courses</h2>
// index.jsp
<%@ page language="java" contentType="text/html; charset=UTF-8"
<%@ taglib prefix="form" uri="http://www.springframework.org/tags/form"%>
<%@ taglib prefix="security" uri="http://www.springframework.org/security/tags"%>
<!DOCTYPE html>
<meta charset="UTF-8">
<title>Home Page</title>
<h2>Welcome to Studytonight!</h2>
<a href="java-course">Study Java</a>
// pom.xml
This file contains all the dependencies of this project such as spring jars, servlet jars, etc. Put these dependencies into your project to run the application.
<project xmlns="http://maven.apache.org/POM/4.0.0"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
<!-- https://mvnrepository.com/artifact/javax.servlet/servlet-api -->
<!-- https://mvnrepository.com/artifact/javax.servlet/javax.servlet-api -->
<!-- https://mvnrepository.com/artifact/jstl/jstl -->
<!-- https://mvnrepository.com/artifact/javax.servlet.jsp/javax.servlet.jsp-api -->
<!-- https://mvnrepository.com/artifact/javax.servlet.jsp.jstl/jstl-api -->
<!-- https://mvnrepository.com/artifact/javax.xml.bind/jaxb-api -->
<!-- https://mvnrepository.com/artifact/org.springframework.security/spring-security-web -->
<!-- https://mvnrepository.com/artifact/org.springframework.security/spring-security-config -->
<!-- https://mvnrepository.com/artifact/org.springframework.security/spring-security-taglibs -->
Project Structure
After creating these files our project will look like the below. You can refer to this to understand the directory structure of the project.
Run the Application
After successfully completing the project and adding the dependencies run the application and you will get the output as below. It renders a login page to authenticate the user.
It will match the username and password with the credentials provided in the spring-security.xml file.
Provide the Correct username and passwords
Home page
Now, you are successfully logged in to the application. This is our index.jsp file renders as a home page to the browser.
See, the application works fine with XML configuration as well. So, you can use any of the configuration for you application.