{"repo":"noel-mugisha/Spring-Auth-Service","free":true,"listed":false,"github":"https://github.com/noel-mugisha/Spring-Auth-Service","clone":"git clone https://github.com/noel-mugisha/Spring-Auth-Service.git","description":"A comprehensive security repo for modern Java backend applications. The only identity provider you’ll ever need.","language":"Java","stars":113,"topics":["authentication","authorization","backend","java","oauth2","security","spring","spring-security","mfa-authenticator","jwt"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Enterprise Spring Boot Authentication Service A comprehensive, production-ready authentication and user management service built with Spring Boot. This service provides robust security features including JWT-based authentication, refresh token rotation with HttpOnly cookies, OAuth2 social login (Google), email verification with OTP, password reset workflows, rate limiting, and database migrations. Designed for modern web applications requiring secure, scalable user authentication and authorization. --- Highlights - Multi-Authentication Support : JWT-based authentication with OAuth2 social login (Google) - Multi-Factor Authentication : TOTP-based MFA (RFC 6238) compatible with Google Authenticator, Authy, and any standard authenticator app — with QR code enrollment, manual secret entry, and 10 single-use recovery codes - Secure Token Management : Refresh token rotation with one-time use and server-side revocation - Stateless APIs : Short-lived JWT access tokens (15 min) with HttpOnly, Secure cookies for refresh tokens (XSS-safe) - Hashed Token Storage : SHA-256 hashed refresh tokens stored securely in database - Rate Limiting : Bucket4j-based rate limiting on authentication endpoints (10 requests/min per IP) - Email Workflows : Event-driven email OTP registration and password reset with secure links - Role-Based Access Control : RBAC with method-level security using @PreAuthorize annotations - Database Migrations : Versioned schema management with Flyway - API Documentation : ","default_branch":null,"files":null,"tree":[],"storefront":"/r/noel-mugisha","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/noel-mugisha/Spring-Auth-Service/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}