Quarkus Security Review
Best practices for securing Quarkus applications with authentication, authorization, and input validation.
When to Activate
- Adding authentication (JWT, OIDC, Basic Auth)
- Implementing authorization with @RolesAllowed or SecurityIdentity
- Validating user input (Bean Validation, custom validators)
- Configuring CORS or security headers
- Managing secrets (Vault, environment variables, config sources)
- Adding rate limiting or brute-force protection
- Scanning dependencies for CVEs
- Working with MicroProfile JWT or SmallRye JWT
Authentication
JWT Authentication
Configuration (application.properties):
Custom Authentication Filter
Authorization
Role-Based Access Control
Programmatic Security
Input Validation
Bean Validation
Custom Validators
SQL Injection Prevention
Panache Active Record (Safe by Default)
Native Queries (Use Parameters)
Password Hashing
CORS Configuration
Secrets Management
HashiCorp Vault Integration
Rate Limiting
Security Note: Never use X-Forwarded-For directly — clients can spoof it.
Use the actual remote address from the servlet request, or an authenticated
identity (API key, JWT subject) when available.
Security Headers
Audit Logging
Dependency Security Scanning
Best Practices
- Always use HTTPS in production
- Enable JWT or OIDC for stateless authentication
- Use
@RolesAllowedfor declarative authorization - Validate all input with Bean Validation
- Hash passwords with BCrypt (never plaintext)
- Store secrets in Vault or environment variables
- Use parameterized queries to prevent SQL injection
- Add security headers to all responses
- Implement rate limiting for public endpoints
- Audit sensitive operations
- Keep dependencies updated and scan for CVEs
- Use SecurityIdentity for programmatic checks
- Set appropriate CORS policies
- Test authentication and authorization paths


