The only thing better than a Maven archetype is a repo you can fork with everything already setup to speed up the creation of new Spring Boot based Web applications, just fork-and-code.
This repository contains a recipe/scaffolding for bootstrapping a Monolithic Web Application with the features & Technology stack listed below. Delete the sample code (or keep it.) and add your own, youโre good to go.
Essentially it's a simple on-demand application backend for rapid prototyping.
Documentation: anantharajuc.github.io/Spring_Boot_Starter_Template ยท documents/ ยท Swagger UI at /swagger-ui.html when running.
Features include but not limited to:
- Spring Boot 4.1 on Java 21 with Spring Security 7, Spring Data JPA, Flyway (H2 and MySQL) and Thymeleaf with Bootstrap 5
- Authentication: form login with remember-me and CSRF protection for the web UI; RS256 JWT access tokens with rotating, single-use refresh tokens for the REST API; sign-up with e-mail verification; login throttling
- User Roles: role and permission based access control, RBAC user management API
- API: rate limiting per API key, HATEOAS links, RFC 9457 problem details, OpenAPI 3 / Swagger UI
- User Profiles
- Internationalization (i18n), dark mode
- Actuator with Prometheus metrics, Docker image and Compose setup, GitHub Actions CI, integration tests, JaCoCo coverage
Explore the docs ยป
Report Bug
ยท
Request Feature
| Service | Badge | Badge | Badge | Badge | Badge |
|---|---|---|---|---|---|
| GitHub | |||||
| GitHub | |||||
| Build/Quality | |||||
| Others | |||||
| Tech | |||||
| Docker | |||||
| Security |
Requirements: Java 21. Maven is provided through the wrapper.
./mvnw spring-boot:run # http://localhost:8080 , in-memory H2 database (default "test" profile)
./mvnw verify # tests + coverage report in target/site/jacoco/index.htmlSeeded users (password password): Admin1, Admin2 (ROLE_ADMIN), AdminTrainee1, AdminTrainee2 (ROLE_ADMINTRAINEE), johndoe, janedoe (ROLE_PERSON).
Change or remove them before exposing an instance.
| What | Where |
|---|---|
| Web UI (form login, CSRF protected) | /sbat/index |
| REST API (JWT bearer token or HTTP Basic) | /api/**, /rbac/** (admin only) |
| Swagger UI / OpenAPI document (not in production) | /swagger-ui.html, /v3/api-docs |
| Actuator: health and info are public, the rest needs ROLE_ADMIN | /actuator/** |
| H2 console (test profile, localhost only) | /h2-console |
# 1. Login: returns a short lived access token and a single use refresh token
curl -s -X POST localhost:8080/api/v1/auth/login -H 'Content-Type: application/json' \
-d '{"username":"Admin1","password":"password"}'
# 2. Call the API with the access token (the person APIs are also rate limited per X-api-key)
curl -s localhost:8080/api/v1/person -H "Authorization: Bearer $ACCESS_TOKEN" -H 'X-api-key: FX001-demo'
# 3. Exchange the refresh token for a new pair; the old refresh token stops working
curl -s -X POST localhost:8080/api/v1/auth/refresh/token -H 'Content-Type: application/json' \
-d "{\"token\":\"$REFRESH_TOKEN\"}"Common settings live in src/main/resources/application.properties; the dev, qa, staging and production
profiles use MySQL and only override what differs. Everything environment specific is read from environment
variables, or from a git-ignored .env file (see .env.example).
| Variable | Purpose |
|---|---|
SPRING_PROFILES_ACTIVE |
test (default, H2), dev, qa, staging, production |
DB_HOST, DB_PORT, DB_DATABASE, DB_USERNAME, DB_PASSWORD |
MySQL connection |
JWT_KEY_STORE, JWT_KEY_STORE_PASSWORD, JWT_KEY_ALIAS |
RSA key used to sign access tokens. Required in production: without it a throw-away key is generated at startup and tokens stop working on restart |
REMEMBER_ME_KEY |
Secret for remember-me cookies, random per start when unset |
MAIL_HOST, MAIL_PORT, MAIL_USERNAME, MAIL_PASSWORD |
SMTP server for sign-up verification e-mails |
BASE_URL |
Public URL used in verification links |
FORWARD_HEADERS_STRATEGY |
Set to native or framework when running behind a reverse proxy |
Create a JWT signing key store (keep it out of the repository):
mkdir -p secrets
keytool -genkeypair -alias sbat -keyalg RSA -keysize 2048 -validity 3650 \
-storetype PKCS12 -keystore secrets/jwt.p12 -dname "CN=sbat"Security note: earlier versions of this repository committed a JWT key store (
redditclone.jks) and an SSL key store, with their passwords. Both have been removed, but they remain in the Git history: if you deployed an earlier version, generate new keys as shown above and never reuse those files.
export DB_PASSWORD=... DB_ROOT_PASSWORD=... JWT_KEY_STORE_PASSWORD=... REMEMBER_ME_KEY=$(openssl rand -base64 32)
docker compose up --build # MySQL 8.4 + the application in the production profileMore Screenshots
- Technology stack & other Open-source libraries
- Technical Functionalities and To-Do
- Online documentation
- Getting Started
- Architecture
- Installation
- Deployment
- Authentication & Security
- User Roles
- Docker
- Testing API
- Changelog
- Code Coverage
- Documentation
This Project uses GitHub's integrated issue tracking system to record bugs and feature requests. If you want to raise an issue, please follow the recommendations below:
- Before you log a bug, please search the issue tracker to see if someone has already reported the problem.
- If the issue doesn't already exist, create a new issue
- Please provide as much information as possible with the issue report.
- If you need to paste code, or include a stack trace use Markdown +++```+++ escapes before and after your text.
Contributions are what make the open source community such an amazing place to be learn, inspire, and create. Any contributions you make are greatly appreciated.
Kindly refer to CONTRIBUTING.md for important Pull Request Process details
-
In the top-right corner of this page, click Fork.
-
Clone a copy of your fork on your local, replacing YOUR-USERNAME with your Github username.
git clone https://github.com/YOUR-USERNAME/Spring-Boot-Application-Template.git -
Create a branch:
git checkout -b <my-new-feature-or-fix> -
Make necessary changes and commit those changes:
git add .git commit -m "new feature or fix" -
Push changes, replacing
<add-your-branch-name>with the name of the branch you created earlier at step #3. :git push origin <add-your-branch-name> -
Submit your changes for review. Go to your repository on GitHub, you'll see a Compare & pull request button. Click on that button. Now submit the pull request.
That's it! Soon I'll be merging your changes into the master branch of this project. You will get a notification email once the changes have been merged. Thank you for your contribution.
Kindly follow Conventional Commits to create an explicit commit history. Kindly prefix the commit message with one of the following type's.
build : Changes that affect the build system or external dependencies (example scopes: gulp, broccoli, npm)
ci : Changes to our CI configuration files and scripts (example scopes: GitHub Actions, Dependabot)
docs : Documentation only changes
feat : A new feature
fix : A bug fix
perf : A code change that improves performance
refactor: A code change that neither fixes a bug nor adds a feature
style : Changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc)
test : Adding missing tests or correcting existing tests
Distributed under the MIT License. See LICENSE.md for more information.
In the end, I hope you enjoyed the application and find it useful, as I did when I was developing it to create a Spring Boot web application template with good/convenient practices for rapid prototyping.
If you would like to enhance, please:
-
Open PRs,
-
Give feedback,
-
Add new suggestions, and
-
Finally, give it a ๐.
-
Happy Coding ...* ๐
Anantha Raju C - @anantharajuc - arcswdev@gmail.com
Project Link: https://github.com/Spring-Boot-Framework/Spring-Boot-Application-Template