Expert · 5–6 weeks
Identity & Access Management Platform
Central auth server issuing OAuth2 tokens, RBAC + ABAC policies, service-to-service mTLS or client credentials, and admin UI for role management.
Why this project
Security architecture is core to staff roles. OAuth2/OIDC depth impresses interviewers.
Tech stack
Java 17Spring Authorization ServerOAuth2OIDCPostgreSQLRedis
Skills demonstrated
- OAuth2 flows
- RBAC/ABAC
- Token lifecycle
- Security architecture
Interview talking points
- OAuth2 flow you implemented
- RBAC vs ABAC when
- Token revocation strategy
- Handling compromised refresh token
Problem statement
Central auth server issuing OAuth2 tokens, RBAC + ABAC policies, service-to-service mTLS or client credentials, and admin UI for role management.