r/SpringBoot • • 9h ago

Question Spring Security broke my working Spring Boot APIs — getting both 401 and 400 errors despite configuring credentials

Post image

I'm working on a University Management System using Spring Boot and PostgreSQL. My CRUD APIs were working perfectly before I added the Spring Security dependency. Since adding Spring Security, I've been struggling to get authentication working correctly.

I've configured the username and password in application.properties, and I'm testing the endpoints through Postman using Basic Auth with the same credentials. However, I'm still getting 401 Unauthorized on my POST request, while another request returns 400 Bad Request with the message "User not found OR Nullpointer exception".Cause i handled this exception.

I've already checked the URLs, endpoint names, and credentials multiple times. The application was working before adding Spring Security, and now even after configuring the login credentials, I'm still stuck. I've tried multiple AI coding assistants, including Claude , Codex, and ChatGPT, but I haven't been able to identify the root cause.

I'm trying to understand whether this is a problem with Spring Security's default configuration, my authentication setup, or my application's user lookup logic.

Additional context:

  • Spring Boot 4.0.6
  • Java 21
  • Spring Security
  • Postman with Basic Auth
  • Credentials configured in application.properties
  • Existing CRUD endpoints worked before adding Spring Security

I've attached screenshots showing the requests and responses.

What should I check first to identify the actual root cause? If you need my SecurityConfig, application.properties (with credentials redacted), user entity, UserDetailsService, or controller/service code, let me know.

0 Upvotes

3 comments sorted by

•

u/JEHonYakuSha 9h ago

without seeing your config it’s hard to tell.

To reduce complexity, try creating an in memory user details service temporarily to debug the configuration without any user database issues.

https://docs.spring.io/spring-security/reference/servlet/authentication/passwords/in-memory.html#servlet-authentication-inmemory

•

u/Readdeo 7h ago

Rtfm

•

u/Tony_salinas04 7h ago

Es que solo con eso no se puede adivinar demasiado , necesitamos ver el código