Joe Grandja

Joe Grandja

Joe Grandja is a core committer on the Spring Security team. He has been leading the efforts in building the next generation of OAuth2 and OpenID Connect support in Spring Security and Spring Authorization Server.

With over 25 years of industry experience, Joe has been a Solution Architect, a Software Engineer, a Team Lead, and a Consultant. His past experience has been mainly focused in the Financial Services sector in the Toronto, Canada, area. He has designed, built, and delivered enterprise grade banking applications and platforms in the Personal and Commercial and Brokerage and Investing divisions. He has worked closely with the InfoSec teams within banks to ensure security and regulatory compliance.

Recent Blog posts by Joe Grandja

Spring Authorization Server 0.0.2 available now

Releases | October 15, 2020 | ...
On behalf of the team and everyone who has contributed, it is my pleasure to announce the general availability of Spring Authorization Server 0.0.2. You can download it from repo.spring.io and Maven Central by using the module coordinates: For additional details on this new project, see the initial announcement and project page. The main features delivered in this release are: Proof Key for Code Exchange by OAuth Public Clients (PKCE) — RFC 7636 User Consent page for OAuth 2.0 Authorization Code Grant — RFC 6749 See the release notes for complete details. To get started using Spring…

Get the very first bits of Spring Authorization Server 0.0.1 !

Releases | August 21, 2020 | ...
On behalf of the team and everyone who has contributed, we are very excited to deliver the very first bits of Spring Authorization Server in the 0.0.1 release! You can download it from repo.spring.io and Maven Central by using the module coordinates: For additional details on this new project, see the initial announcement and project page. The main features delivered in this initial release are: OAuth 2.0 Authorization Code Grant — RFC 6749 OAuth 2.0 Client Credentials Grant — RFC 6749 JSON Web Token (JWT) — RFC 7519 JSON Web Signature (JWS) — RFC 7515 JSON Web Key (JWK) — RFC 7517 Key…

Spring Security OAuth 2.5.0 Released

Releases | May 28, 2020 | ...
I’m pleased to announce the release of Spring Security OAuth 2.5.0. End-of-Life Notice The 2.5.0 release is the final minor release. See the announcement for further details. Project Page | GitHub | Documentation | Help

End-of-Life for Spring Security OAuth

Engineering | May 07, 2020 | ...
In January 2018, we announced that the Spring Security OAuth (legacy) project is officially in maintenance mode. Later in November of 2019, we provided an update in the Spring Security OAuth 2.0 Roadmap, stating that the 2.3.x line will reach end-of-life in March 2020. The currently supported version branches are 2.4.x and 2.5.x, with the 2.5.0 release scheduled for May 2020, which will be the final minor release. To that end, the plan is to provide patch and security fixes for the 2.4.x and 2.5.x line until May 2021. Additionally, security fixes will be supported for the 2.5.x line until May…

Spring Security 5.2.2, 5.1.8 and 5.0.14 Released

Releases | February 05, 2020 | ...
On behalf of the community, I’m pleased to announce the release of Spring Security 5.2.2 (release notes), 5.1.8 (release notes) and 5.0.14 (release notes). These releases deliver bug fixes along with some minor improvements. Users are encouraged to update to the latest patch release. Project Site | Reference | Help

Spring Security OAuth 2.4.0, 2.3.8 Released

Releases | November 14, 2019 | ...
I’m pleased to announce the releases of Spring Security OAuth 2.4.0 and 2.3.8. Deprecation Notice The 2.4.0 release officially deprecates all classes. The latest OAuth 2.0 support is provided by Spring Security. See the announcement for further details. For a complete list of changes, please refer to: 2.4.0 changelog 2.3.8 changelog Project Page | GitHub | Documentation | Help

Spring Security OAuth 2.3.7, 2.2.6, 2.1.6, 2.0.19 Released

Releases | October 17, 2019 | ...
I’m pleased to announce the releases of Spring Security OAuth 2.3.7, 2.2.6, 2.1.6 and 2.0.19. These maintenance releases primarily deliver bug fixes and minor enhancements. For a complete list of changes, please refer to: 2.3.7 changelog 2.2.6 changelog 2.1.6 changelog 2.0.19 changelog Project Page | GitHub | Documentation | Help

Spring Security 5.1.5, 5.0.12, 4.2.12 Released

Releases | April 03, 2019 | ...
On behalf of the community I am pleased to announce the release of Spring Security 5.1.5 (changelog), 5.0.12 (changelog), and 4.2.12 (changelog). These releases deliver bug fixes along with some minor improvements. Users are encouraged to update to the latest patch release. Project Site | Reference | Help

CVE-2019-3778: Spring Security OAuth 2.3.5, 2.2.4, 2.1.4, 2.0.17 Released

Releases | February 21, 2019 | ...
We have released Spring Security OAuth 2.3.5, 2.2.4, 2.1.4 and 2.0.17 to address CVE-2019-3778: Open Redirector in spring-security-oauth2. Please review the information in the CVE report and upgrade immediately. For additional changes included in each release, please refer to: 2.3.5 changelog 2.2.4 changelog 2.1.4 changelog 2.0.17 changelog NOTE: For users of Spring Boot 1.5.x and Spring IO Platform Cairo, it is highly recommended to override the spring-security-oauth version to the latest version containing the fix for the CVE. Please see the Mitigation section in the CVE report for detailed…

Spring Security OAuth 2.3.4, 2.2.3, 2.1.3, 2.0.16 Released

Releases | October 16, 2018 | ...
I’m pleased to announce the releases of Spring Security OAuth 2.3.4, 2.2.3, 2.1.3 and 2.0.16. The releases address a vulnerability. Please see this blog post published after the associated Spring Boot 2.0.6 and 1.5.17 releases. For a list of changes, please refer to: 2.3.4 changelog 2.2.3 changelog 2.1.3 changelog 2.0.16 changelog Project Page | GitHub | Documentation | Help

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all