A secure Java Spring Boot application for managing student records with authentication, role-based access, validation, search, and a lightweight web dashboard.
The Student Management System is a backend-focused web application built with Java, Spring Boot, Spring Security, and MySQL. It provides authenticated operations for managing student records through REST APIs and a simple HTML-based interface.
The project demonstrates practical Spring Boot fundamentals including layered application design, JPA persistence, security configuration, validation, and environment-based configuration.
| Feature | Description |
|---|---|
| 🔐 Authentication | Login/logout with Spring Security |
| 👥 Authorization | Role-based access with ADMIN-only deletion |
| 🎓 Student Management | Add, edit, search, view, and delete students |
| 🔎 Search & Filters | Search by name/email and filter by course |
| 📊 Dashboard | Student statistics and overview |
| ✅ Validation | Input validation for student operations |
| 🗄️ Persistence | MySQL database with Spring Data JPA |
| 🔒 Security | BCrypt password encoding, CSRF protection, session controls |
| ⚙️ Configuration | Credentials and deployment settings via environment variables |
HTML Frontend
│
│ HTTP / REST
▼
┌─────────────────────┐
│ Spring Boot │
│ Controller Layer │
└──────────┬──────────┘
▼
┌─────────────────────┐
│ Service Layer │
│ Business Logic │
└──────────┬──────────┘
▼
┌─────────────────────┐
│ Repository Layer │
│ Spring Data JPA │
└──────────┬──────────┘
▼
MySQL Database
| Technology | Purpose |
|---|---|
| Java 17 | Application language |
| Spring Boot 3.2.0 | Application framework |
| Spring Security 6.x | Authentication and authorization |
| Spring Data JPA 3.x | Persistence and database access |
| MySQL 8.x | Relational database |
| Lombok | Boilerplate reduction |
| Maven 3.x | Build and dependency management |
| HTML/CSS/JavaScript | Frontend interface |
src/main/
├── java/com/student/
│ ├── StudentManagementApplication.java
│ ├── DataInitializer.java
│ ├── config/
│ │ └── SecurityConfig.java
│ ├── model/
│ │ ├── Student.java
│ │ └── Admin.java
│ ├── repository/
│ │ ├── StudentRepository.java
│ │ └── AdminRepository.java
│ ├── service/
│ │ └── StudentService.java
│ └── controller/
│ ├── StudentController.java
│ └── DashboardController.java
└── resources/
├── application.properties
├── application-prod.properties
└── static/
├── login.html
├── dashboard.html
└── index.html
| Method | Endpoint | Purpose |
|---|---|---|
| GET | /api/students |
List students |
| GET | /api/students/{id} |
Get a student |
| POST | /api/students |
Add a student |
| PUT | /api/students/{id} |
Update a student |
| DELETE | /api/students/{id} |
Delete a student (ADMIN) |
| GET | /api/students/search?name=... |
Search by name |
| GET | /api/students/course/{course} |
Filter by course |
Protected operations require authentication according to the application's security configuration.
- Java 17
- Maven 3.x
- MySQL 8.x
CREATE DATABASE IF NOT EXISTS studentdb;Keep credentials in environment variables rather than committing secrets.
Example values:
ADMIN_USERNAME=your_username
ADMIN_PASSWORD=your_strong_password
DB_URL=jdbc:mysql://localhost:3306/studentdb
DB_USERNAME=root
DB_PASSWORD=your_password
PORT=8082
mvn spring-boot:runhttp://localhost:8082/
The project includes:
- Spring Security authentication
- BCrypt password encoding
- Role-based authorization
- CSRF protection
- Session management
- Environment-based credentials
- Production-oriented error handling
Never commit
.env, production credentials, API keys, or local database passwords.
The project includes configuration guidance for deployment on Render, including environment variables and Maven build/start commands.
This project demonstrates practical experience with:
- Spring Boot REST API development
- Spring Security configuration
- JPA/Hibernate persistence
- MySQL database integration
- Role-based authorization
- Validation and error handling
- Environment-based configuration
Prashant Maurya
Java Full Stack Developer
GitHub: @prashantpiyush1111
See the repository license for current usage terms.