A RESTful blog platform backend built with Java, Spring Boot, PostgreSQL, Spring Data JPA, Spring Security, and JWT.
The backend provides APIs for user authentication, blog posts, categories, and tags, with support for draft and published posts, relational persistence, request validation, and stateless JWT-based authentication.
- User authentication with JWT
- Stateless Spring Security configuration
- Create, read, update, and delete blog posts
- Draft and published post states
- Retrieve draft posts for the authenticated user
- Filter published posts by category and tag
- Category management
- Tag management
- Post–category relationships
- Post–tag many-to-many relationships
- DTO-based API responses
- MapStruct entity/DTO mapping
- Request validation
- Centralized error handling
- PostgreSQL persistence
- Docker Compose development environment
| Technology | Purpose |
|---|---|
| Java 21 | Backend language |
| Spring Boot | Application framework |
| Spring Web | REST API |
| Spring Data JPA | Persistence |
| Hibernate | ORM |
| Spring Security | Authentication |
| JWT / JJWT | Token-based authentication |
| PostgreSQL | Relational database |
| MapStruct | DTO/entity mapping |
| Lombok | Boilerplate reduction |
| Maven | Build management |
| Docker Compose | Local infrastructure |
The application follows a layered backend architecture:
Client
│
▼
Controllers
│
▼
Services
│
▼
Repositories
│
▼
PostgreSQL
Security is applied at the request boundary:
Client
│
│ Authorization: Bearer <JWT>
▼
Spring Security
│
▼
JWT Authentication Filter
│
▼
Security Context
│
▼
Controller
│
▼
Service
│
▼
Repository
│
▼
PostgreSQL
src/main/java/com/sachin/blog/
├── config/
├── controllers/
├── domain/
│ ├── dtos/
│ └── entities/
├── mappers/
├── repositories/
├── security/
├── services/
└── BlogApplication.java
The core domain consists of:
User
│
│ authors
▼
Post
├── belongs to → Category
└── has many → Tag
Posts support two states:
DRAFT
PUBLISHED
- A user can author multiple posts.
- Each post has a single author.
- A post belongs to a category.
- Categories exist independently from posts.
- A post can have multiple tags.
- A tag can belong to multiple posts.
- The relationship is represented using a join table.
All endpoints are versioned under:
/api/v1
| Method | Endpoint | Description |
|---|---|---|
POST |
/api/v1/auth/login |
Authenticate a user and receive a JWT |
| Method | Endpoint | Description |
|---|---|---|
GET |
/api/v1/posts |
Get published posts |
POST |
/api/v1/posts |
Create a post |
GET |
/api/v1/posts/{id} |
Get a specific post |
PUT |
/api/v1/posts/{id} |
Update a post |
DELETE |
/api/v1/posts/{id} |
Delete a post |
GET |
/api/v1/posts/drafts |
Get draft posts for the authenticated user |
| Method | Endpoint | Description |
|---|---|---|
GET |
/api/v1/categories |
Get all categories |
POST |
/api/v1/categories |
Create a category |
DELETE |
/api/v1/categories/{id} |
Delete a category |
| Method | Endpoint | Description |
|---|---|---|
GET |
/api/v1/tags |
Get all tags |
POST |
/api/v1/tags |
Create a tag |
DELETE |
/api/v1/tags/{id} |
Delete a tag |
The application uses Spring Security with JWT-based authentication.
The authentication flow is:
POST /api/v1/auth/login
│
▼
Authenticate credentials
│
▼
Generate JWT
│
▼
Return token to client
│
▼
Authorization: Bearer <JWT>
│
▼
JWT Authentication Filter
│
▼
Security Context
│
▼
Protected API
The application uses stateless authentication rather than server-side sessions.
Note: Resource-level authorization is not currently implemented.
PostgreSQL is used as the relational database.
Spring Data JPA provides repository abstractions, while Hibernate handles ORM and entity persistence.
Service
│
▼
Repository
│
▼
Spring Data JPA
│
▼
Hibernate
│
▼
PostgreSQL
Custom repository queries are used for post filtering based on publication status, category, and tags.
The API uses DTOs to separate the HTTP/API representation from persistence entities.
Request
│
▼
DTO
│
▼
Service
│
▼
Entity
│
▼
Database
MapStruct is used for entity-to-DTO and DTO-to-entity mapping.
- Java 21+
- Maven
- Docker
- Docker Compose
- Git
git clone https://github.com/s4chinjha/blog_platform_backend.git
cd blog_platform_backenddocker compose up -dUsing the Maven wrapper:
./mvnw spring-boot:runOr using Maven:
mvn spring-boot:runThe local database administration interface is available at:
http://localhost:8888
Backend implementation complete.
The repository contains the core blog platform backend, including REST APIs, JPA relationships, PostgreSQL persistence, DTO mapping, validation, JWT authentication, Spring Security, and Docker-based local development.
Resource-level authorization is not currently implemented.
Additional project documentation is available in docs/:
- Learning Notes — implementation notes and concepts explored during development.
- Future Improvements — planned extensions and engineering improvements.
- Credits — project references.