Java, Spring Boot and Vue
Integrate protected video with Spring Security and a server-owned content catalog, then render it with Vue.
Comment la lecture est autorisée
Votre backend décide qui peut regarder le contenu. DRM-X fournit l’autorisation de lecture. Le lecteur l’utilise pour demander une licence DRM.
- Spectateur
Se connecte à votre service et demande une vidéo.
- Votre backend
Vérifie l’achat, l’abonnement ou toute autre autorisation d’accès de l’utilisateur.
- DRM-X
Applique les règles choisies et renvoie la configuration ainsi que l’autorisation de lecture.
- Lecteur
Utilise l’autorisation reçue pour demander la licence DRM nécessaire à la lecture.
Build and configure the backend#
The sample uses Java 21, Spring Boot 3.5.11, Spring Security and JDBC. Build it with Maven. Set DRMX_SITE_ID, DRMX_SITE_KEY, DRMX_ACCESS_KEY and DRMX_INSTANCE_ID on the server. Bind a persistent database through DRMX_DATABASE_URL for deployment.
mvn test
mvn package
java -jar target/drmx-java-vue-1.3.0-SNAPSHOT.jar
The default H2 database is empty and held in memory. No demo account or content is authorized automatically. Connect your existing Spring Security account service, or provision users and authorities using Spring’s JdbcUserDetailsManager with encoded passwords.
Connect your content and access rules#
Create drmx_video records with the published Content ID, content type, policy and enabled state. drmx_access binds a username to one video with start, expiry and revocation fields. VideoRepository.authorized checks these records for every request. Adapt this query to your existing course or subscription tables.
Keep the provided schema only for a new sample database. When integrating an existing production application, use your normal forward-only database migrations and disable automatic schema initialization.
Use the Vue component#
After signing in, fetch /api/drmx/videos/VIDEO_ID. Copy DrmxPlayer.vue and runtime.mjs from web-components, then pass the response contentId, contentType and sessionEndpoint to the component. It loads the pinned Shaka and Universal Player scripts automatically and replaces the old player when the selected video changes. Keep the player and authenticated session endpoint on the same origin.
The endpoint URL includes Spring Security’s CSRF token. Do not strip it when passing the URL to the component. The backend rechecks the video mapping and access before calling DRM-X. Local Java tests cover policy construction, enrollment, account isolation and revocation.
DRM-X 6.0