Posts

Showing posts with the label Spring Cloud Gateway

A New Collection of Thoughtful Learning Apps — Now Available on iOS & Android

Image
I’m excited to share a set of mobile apps I’ve recently completed and published on both the Google Play Store and the Apple App Store. These apps are designed with a simple goal in mind: to make meaningful, structured content more accessible, whether you’re studying theology or improving your English vocabulary. 📱 Now Available on Both Platforms All apps are live and available for download: Google Play Developer Page: https://play.google.com/store/apps/dev?id=5835943159853189043 Apple App Store Developer Page: https://apps.apple.com/ca/developer/q-z-l-corp/id1888794100 📖 Theology & Confession Study Apps For those interested in Reformed theology and classical Christian teachings, I’ve developed a series of apps that present foundational texts in a clean, focused reading format: The Belgic Confession Canons of Dort Heidelberg Catechism Westminster Shorter Catechism Each app is designed to provide a distraction-free experience, making it easier to read, reflect, and revisit these im...

Spring Boot 4 Upgrade Pitfalls Guide: Java 21, Jakarta, Jackson 3, and Copilot Automation

Image
Spring Boot 4 Upgrade Pitfalls Guide: Java 21, Jakarta, Jackson 3, and Copilot Automation Spring Boot 4 introduces major ecosystem changes and many teams are planning to upgrade their applications to Java 21 and Spring Boot 4.0.x . However, real-world upgrades often reveal multiple compatibility issues such as: Jakarta package migration breaking compilation Jackson 3 JSON behavior changes Spring Cloud Gateway configuration updates Test framework migration issues Micrometer / Observability runtime errors This article summarizes a production-ready upgrade strategy and demonstrates how to use GitHub Copilot Agent to automate much of the migration work. Table of Contents Why Upgrade to Spring Boot 4 Recommended Upgrade Strategy Using GitHub Copilot for Automated Migration Java 21 Upgrade Spring Boot 4 Upgrade Jakarta Migration Jackson 3 Changes Spring Cloud Gateway Changes Common Upgrade Pitfalls Upgrade Verification Checklist Why Upgrade to Spring...

Spring Boot 4 升级踩坑指南:Java 21、Jakarta、Jackson 3 和 Copilot 自动升级

Image
Spring Boot 4 升级踩坑指南:Java 21、Jakarta、Jackson 3 和 Copilot 自动升级 Spring Boot 4 已经发布,很多团队开始计划将系统升级到 Java 21 与 Spring Boot 4.0.3 。 然而在实际升级过程中,开发者会遇到很多问题,例如: Jakarta 包迁移导致编译失败 Jackson 3 导致 JSON 反序列化变化 Spring Cloud Gateway 配置结构变化 测试依赖和注解迁移 Observability / Micrometer 监控异常 本文总结了一套 企业级 Spring Boot 4 升级流程 , 并介绍如何使用 GitHub Copilot Agent 自动生成升级 PR。 目录 为什么升级 Spring Boot 4 升级总体策略 使用 Copilot 自动升级 Java 21 升级 Spring Boot 4 升级 Jakarta 迁移 Jackson 3 变化 Spring Cloud Gateway 配置变化 常见踩坑 升级验证 Checklist 为什么升级 Spring Boot 4 Spring Boot 4 带来了多个重要变化: 默认支持 Java 21 Jakarta API 全面替换 javax Jackson 3 JSON 生态升级 Micrometer Observability 改进 Spring Security 现代 DSL 对于长期维护的系统来说,升级可以获得: 更好的性能 更安全的依赖 更好的云原生支持 升级总体策略 升级应该按阶段进行: 升级 Java 升级 Spring Boot 进行 Jakarta 迁移 依赖版本对齐 修复配置变化 修复测试 验证运行 每一步都必须 编译 + 测试 + 启动验证 。 使用 Copilot 自动升级 对于大型代码库,手动升级非常耗时。 GitHub Copilot Agent 可以自动分析项目结构, 并生成完整升级 Pull Request。 推荐 Prompt Goal: Upgrade this project ...

一次 403 错误的排查实录:Spring Cloud Gateway、WebFlux、PingFederate 与 CORS

Image
一次 403 错误的排查实录:Spring Cloud Gateway、WebFlux、PingFederate 与 CORS 一次真实的线上排错记录:一个看似 OAuth / JWT / Spring Security 的 403,最终却是 CORS 问题。 背景 我们在一次系统集成过程中,遇到了一个非常令人困惑的问题,涉及以下组件: Spring Cloud Gateway Spring Boot WebFlux 后端服务 PingFederate(OIDC / OAuth2) 本地运行的 React 前端( http://localhost:4200 ) 整体请求流程如下: 用户通过 PingFederate 登录(SSO) 前端获取 access token 前端发起 POST 请求 → Gateway → 后端服务 在以下场景中,一切都运行正常: 使用 Postman 直接调用后端 绕过 Gateway,直接调用后端 所有组件都在本地运行 但一旦请求通过 部署在 OpenShift 中的 Spring Cloud Gateway ,所有 POST 请求都会失败,并返回: 403 Forbidden 为什么这个问题如此迷惑 完全相同的 access token,在 Postman 中可以正常使用 GET 请求成功,POST 请求失败 系统中没有配置任何 role 或 scope 校验 不同环境下 401 / 403 的表现不一致 JWT 的 issuer、audience、签名全部正确 所有线索一开始都指向 OAuth 或 PingFederate 的配置问题——但这个判断是错误的。 关键线索:问题是如何被定位出来的 1. Postman 成功,浏览器失败 同一个请求,在不同客户端表现完全不同: Postman → 成功 浏览器(经 Gateway)→ 403 这一步非常关键,它强烈暗示: 问题并不在 token 本身 。 2. 在 Postman 中加上 Origin 头,请求立刻失败 我们在 Postman 中手动加入以下 header: O...

Debugging 403 Errors with Spring Cloud Gateway, WebFlux, PingFederate, and CORS

Image
Debugging 403 Errors with Spring Cloud Gateway, WebFlux, PingFederate, and CORS A real-world postmortem on a confusing 403 that turned out not to be OAuth, JWT, or Spring Security — but CORS. Background We recently ran into a frustrating issue while integrating: Spring Cloud Gateway Spring Boot WebFlux backend PingFederate (OIDC / OAuth2) A React frontend running locally ( http://localhost:4200 ) The request flow looked like this: User logs in via PingFederate (SSO) Frontend receives an access token Frontend sends POST requests → Gateway → Backend service Everything worked perfectly when: Calling the backend directly via Postman Calling the backend directly without the gateway Running everything locally But once the request went through Spring Cloud Gateway in OpenShift , all POST requests failed with: 403 Forbidden Why This Was Confusing The same access token worked in Postman GET requests succeeded, POST requests fa...