DRM-X 6.0 dove and olive branch logoDRM-X 6.0Docs
◎ English

Java, Spring Boot and Vue

Integrate protected video with Spring Security and a server-owned content catalog, then render it with Vue.

View MarkdownLive examplesUpdated 2026-09-15

How playback is authorized

Your backend decides who can watch. DRM-X provides playback authorization. The player uses that authorization to request a DRM license.

  1. Viewer

    Signs in to your service and requests a video.

  2. Your backend

    Checks the user's purchase, subscription, or other permission to watch.

  3. DRM-X

    Applies the selected playback rules and returns the playback configuration and authorization.

  4. Player

    Uses the returned authorization to request the DRM license needed for playback.

Your backend decides access; DRM-X enforces the signed policy. Encrypted media and DRM licenses follow separate delivery paths.

Build and configure the backend#

The sample uses Java 21, Spring Boot 3.5.11, Spring Security and JDBC. Build it with Maven. Set DRMX_SITE_ID, DRMX_SITE_KEY, DRMX_ACCESS_KEY and DRMX_INSTANCE_ID on the server. Bind a persistent database through DRMX_DATABASE_URL for deployment.

mvn test
mvn package
java -jar target/drmx-java-vue-1.3.0-SNAPSHOT.jar

The default H2 database is empty and held in memory. No demo account or content is authorized automatically. Connect your existing Spring Security account service, or provision users and authorities using Spring’s JdbcUserDetailsManager with encoded passwords.

Download third-party integration source

Connect your content and access rules#

Create drmx_video records with the published Content ID, content type, policy and enabled state. drmx_access binds a username to one video with start, expiry and revocation fields. VideoRepository.authorized checks these records for every request. Adapt this query to your existing course or subscription tables.

Keep the provided schema only for a new sample database. When integrating an existing production application, use your normal forward-only database migrations and disable automatic schema initialization.

Use the Vue component#

After signing in, fetch /api/drmx/videos/VIDEO_ID. Copy DrmxPlayer.vue and runtime.mjs from web-components, then pass the response contentId, contentType and sessionEndpoint to the component. It loads the pinned Shaka and Universal Player scripts automatically and replaces the old player when the selected video changes. Keep the player and authenticated session endpoint on the same origin.

The endpoint URL includes Spring Security’s CSRF token. Do not strip it when passing the URL to the component. The backend rechecks the video mapping and access before calling DRM-X. Local Java tests cover policy construction, enrollment, account isolation and revocation.