Enhancing Application Security with Spring

Job ID: 37955145

Budget: ₹12,500 – ₹37,500 INR

I'm looking for an experienced Java developer with a deep knowledge of Spring Security and MySQL. The main focus of the project is to implement user authentication, manage authorization and access control, as well as secure the application against potential threats.

Key tasks will include:

Objective:-
To list and document the functional aims of the security module functionalities to be used as
part of the REST API based web or mobile solutions. This module should be generalized to integrate
with any application as a component or module and have to configure the basic security values in the
database.
Functional Aim(s):-
● 100% DB Driven Data & Configurations
● Dynamic User and Role Management (OAuth2.0 based Authentication & Authorization)
● Mobile Number + OTP based Login as the first thing
● Basic Email-ID/Username with password authentication.
● Self (Common) User Profile Management
● MFA Enabled / Configurable Security Authentication
● DB Driven Resource Access Authorization
● Security Audit
● Security Information Tracking
● SSO Implementation
● Security Limits & IP Whitelisting
● User (Personal) Security Settings
● SAML Login Integration
● Cross Platform (Mobile/ Web/ Standalone / API) Support
● Role Based Client App Actions & Menu Links Management
● Security Access Exceptions / Restrictions
● Security Monitoring & Notification
● Inter service communication through Security authorization
● Custom Filter or Interceptor (or some other logic) to validate the subscriber’s access validity
● Single User with Multiple Roles and Multiple Client app access facility
● Security Preferences functionality for subscriber/user to manage from his account.
● Configurable Remember-Me option at the time sign-in
● Additional features like password reset alert for every 6 months or configured time period.
● MPIN / Face Recognition / Thumb for better experience - to maintain or automate the
password entry for mobile apps
● Password Recovery / Reset Mechanisms.
○ Through OTP
○ Through Email
○ Through Standard Generated Keywords or Strings
○ Through Recovery Email ID
● Should be an independent micro service or jar to bundle with or to connect with any java
based REST API Solution for re-use
● Package structure : com.chs.core.security.**
● Should be an complete module with all integrations like logging, aspects(if required),
exceptions, error messages, sonarqube, emma, configurable external properties (for
connecting to database or some other integrations like AWS account)
Data Entities to be maintained:-
User Role Application Channel User Group
EndPoints Resource Service Login History Oauth Tokens
OTP Record OTP Attempts IP Exceptions Txn Audit Request Log
Response Log Exceptions Codes System Params Directories
Key points to be noted:-
● We are going to use Spring Security as part of the Security Module Implementation.
● Spring Data JPA is the base ORM Facility that we gonna use within the application
● Let us have multi datasource connectivity, one for traditional DB Entities and another for
Logging.
● We are going to maintain the entire code base through a GitHub/ Bitbucket account.
● We’ve to prepare a Central maven repo in our AWS account and will have a Dev Infra Setup
to test the Module and e-commerce dev platform.
● From the team, expecting the CI/CD Pipeline planning for the entire project.
● Let us plan some Project SCRUM to track the things.
● Declare the mutual discussion and doubts session for code base review and other
discussions.
● SPOC For the entire Module Development.
● Declare the Deadline for each module.
● Identify the challenges and try to fill them as POC’s prior for validation with CHS.
● Finally ASK for the help in terms of
○ Understanding the functionality or business need
○ Technical assistance
● Key Technical Implementation Are must for every Code base:-
○ Test Cases (using Mockito)
■ For unit & integration testing based on the functional scenarios
○ First Level Documentation (Swagger UI integration)
○ Code Review Plugin validation
○ PostMan Project File to test the REST API
○ Logging & Aspects implementations are must for basic logging
○ Use Common Codebase for CRUD operations.

The perfect candidate is proficient with:

- Java, Spring Boot and Spring Security
- MySQL for database management
- Understanding of secure coding practices
- Previous experience in similar projects

This project requires substantial expertise in Spring Security, making it perfect for a detail-oriented developer with a knack for secure coding. It's imperative that the selected programer is committed to following best practices for secure application development. The developer should also possess a keen eye for potential security leaks in their code.

These tasks will be done using Java as the main language and MySQL for database management. Considering the specialized nature of this project, any similar previous experience will be highly appreciated and beneficial.