cyberneticlibrary

Secure Quarkus endpoints and auth

quarkus-securityskillsetup L20
Sheshiyer/skill-clusters
What it does

Configure JWT/OIDC authentication and role-based access control

Best for

Adding authentication boundaries and role-based access control to Quarkus REST services.

Inputs
  • · REST endpoint requests
  • · JWT tokens
  • · custom credentials
Outputs
  • · secured endpoints
  • · authorization rules
  • · validation configs
Requires
  • · Quarkus
  • · MicroProfile JWT
  • · SmallRye JWT
Preconditions
  • · Quarkus 3.x project with security extensions
Failure modes
  • · Misconfigured JWT issuer grants unauthorized access
  • · missing @RolesAllowed allows all authenticated users
Trust signals
  • · Example code with @Authenticated decorators
  • · MicroProfile JWT spec compliance
  • · CORS/CSRF configuration examples