One Spring Boot application serves a server-rendered admin UI (users log in with a session), a public JSON API used by mobile apps with OAuth2 access tokens, and Actuator endpoints for the platform team. Legal adds a requirement: when an employee is terminated, their access must end within one minute. Design the security configuration, and justify the token validation choice given that requirement.
Three SecurityFilterChain beans, each with its own securityMatcher and an explicit order, because FilterChainProxy runs only the first chain whose matcher matches. The API chain matches /api/**: stateless, bearer tokens through the OAuth2 resource server, CSRF off (no cookie authenticates), 401 on failure. The Actuator chain matches the actuator endpoints with its own rules. The admin UI chain catches the rest: form or OIDC login with a session, CSRF on, redirect to login. For the one-minute requirement, local JWT validation with 15-minute tokens cannot meet it, because a JWT is valid until exp whatever happens to the account. The choices are access tokens of a minute or less with revocable refresh tokens, or introspection, which reflects revocation on the next call at the cost of a network call per request and a runtime dependency on the authorization server. For the admin UI, the session can be invalidated server-side directly.