Joe Grandja

Joe Grandja

Joe Grandja is a core committer on the Spring Security team. He has been leading the efforts in building the next generation of OAuth2 and OpenID Connect support in Spring Security and Spring Authorization Server.

With over 25 years of industry experience, Joe has been a Solution Architect, a Software Engineer, a Team Lead, and a Consultant. His past experience has been mainly focused in the Financial Services sector in the Toronto, Canada, area. He has designed, built, and delivered enterprise grade banking applications and platforms in the Personal and Commercial and Brokerage and Investing divisions. He has worked closely with the InfoSec teams within banks to ensure security and regulatory compliance.

Recent Blog posts by Joe Grandja

Spring Security 5.1.5, 5.0.12, 4.2.12 Released

Releases | April 03, 2019 | ...
On behalf of the community I am pleased to announce the release of Spring Security 5.1.5 (changelog), 5.0.12 (changelog), and 4.2.12 (changelog). These releases deliver bug fixes along with some minor improvements. Users are encouraged to update to the latest patch release. Project Site | Reference | Help

CVE-2019-3778: Spring Security OAuth 2.3.5, 2.2.4, 2.1.4, 2.0.17 Released

Releases | February 21, 2019 | ...
We have released Spring Security OAuth 2.3.5, 2.2.4, 2.1.4 and 2.0.17 to address CVE-2019-3778: Open Redirector in spring-security-oauth2. Please review the information in the CVE report and upgrade immediately. For additional changes included in each release, please refer to: 2.3.5 changelog 2.2.4 changelog 2.1.4 changelog 2.0.17 changelog NOTE: For users of Spring Boot 1.5.x and Spring IO Platform Cairo, it is highly recommended to override the spring-security-oauth version to the latest version containing the fix for the CVE. Please see the Mitigation section in the CVE report for detailed…

Spring Security OAuth 2.3.4, 2.2.3, 2.1.3, 2.0.16 Released

Releases | October 16, 2018 | ...
I’m pleased to announce the releases of Spring Security OAuth 2.3.4, 2.2.3, 2.1.3 and 2.0.16. The releases address a vulnerability. Please see this blog post published after the associated Spring Boot 2.0.6 and 1.5.17 releases. For a list of changes, please refer to: 2.3.4 changelog 2.2.3 changelog 2.1.3 changelog 2.0.16 changelog Project Page | GitHub | Documentation | Help

Spring Security 5.1 goes GA

Releases | September 27, 2018 | ...
On behalf of the community, it is my pleasure to announce the general availability of Spring Security 5.1. This release closes off 50+ tickets. Please check out the What’s New in Spring Security 5.1. As always, we look forward to hearing your feedback! Project Site | Reference | Help

Spring Security OAuth 2.3.3, 2.2.2, 2.1.2, 2.0.15 Released

Releases | May 08, 2018 | ...
I’m pleased to announce the releases of Spring Security OAuth 2.3.3, 2.2.2, 2.1.2 and 2.0.15. These maintenance releases primarily deliver bug fixes. For a complete list of changes, please refer to: 2.3.3 changelog 2.2.2 changelog 2.1.2 changelog 2.0.15 changelog 2018-05-09 Update: The releases address a vulnerability. Please see this blog post published after the associated Spring Boot 1.5.13 release. Project Page | GitHub | Documentation | Help

Spring Security OAuth 2.3.2 Released

Releases | April 12, 2018 | ...
On behalf of the community, I’m pleased to announce the release of Spring Security OAuth 2.3.2.RELEASE. This release resolves a runtime incompatibility issue with RedisTokenStore and Spring Data Redis 2.0.x. See #1319 and #1335. This release also includes a few minor enhancements and bug fixes. Project Page | GitHub | Documentation | Help

Spring Security 5.0.4 and 4.2.5 Released

Releases | April 05, 2018 | ...
I’m pleased to announce the releases of Spring Security 5.0.4 and 4.2.5. Both releases primarily deliver bug fixes and dependency version updates along with some minor improvements. For a complete list of changes, please refer to the 5.0.4 changelog and 4.2.5 changelog. Project Site | Reference | Help

Spring Security OAuth 2.3.0 Released

Releases | March 16, 2018 | ...
On behalf of the community, I’m pleased to announce the release of Spring Security OAuth 2.3.0.RELEASE. The 2.3.0 release adds new support for Elliptic Curve signature verification in JwkTokenStore. Thank you Michael Duergner for this contribution! This release also includes a few minor enhancements and bug fixes. Project Page | GitHub | Documentation | Help

Spring Security OAuth Boot 2 Auto-config 2.0.0 Released

Releases | March 01, 2018 | ...
I’m pleased to announce the release of Spring Security OAuth Boot 2 Auto-config 2.0.0. This project is intended to be used to help users transition between the old Spring Security OAuth 2.x support and the Next Generation OAuth 2.0 Support in Spring Security 5. It provides users of Spring Security OAuth 2.x the same auto-configuration capabilities in a Spring Boot 2.0 based application that is currently available in Spring Boot 1.5.x. For more details please refer to the documentation. GitHub | Reference | Help

Spring Security OAuth 2.3.0.RC1 Released

Releases | February 27, 2018 | ...
On behalf of the community, I’m pleased to announce the release of Spring Security OAuth 2.3.0.RC1. The 2.3.0.RC1 release adds new support for Elliptic Curve signature verification in JwkTokenStore. This release also includes a few minor enhancements and bug fixes. Project Page | GitHub | Documentation | Help

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all