How to create an AI and RAG chatbot using Spring AI and a Web HTML page.
Retrieval-Augmented Generation (RAG)
First, you need to select an LLM (Large Language Model) that Spring AI will use to communicate: Instead of relying solely on an LLM's pre-trained knowledge, RAG fetches relevant context from your own data sources (like databases, PDFs, or internal documentation) at runtime and passes that information along with the user prompt to the LLM.
Step 1: Core Concepts of RAG
Spring AI simplifies RAG integration through familiar Spring abstractions: DocumentReader & TextSplitter: Interfaces to ingest documents (e.g., using Apache Tika) and break them into processable chunks.
VectorStore: A unified Java abstraction for vector databases (supports pgvector, Redis, Pinecone, Qdrant, Milvus, ChromaDB, etc.).
Advisor API (QuestionAnswerAdvisor): A high-level abstraction that automatically intercepts ChatClient prompts, queries the VectorStore, appends retrieved documents to the prompt context, and passes it to the LLM.
RetrievalAugmentationAdvisor: A modular API for advanced RAG patterns, enabling features like multi-query expansion, document re-ranking, and dynamic metadata filtering.
Step 2: Implementing Basic RAG with Spring AI
In this step, we configure the Spring Boot AI application using Spring Initializr (https://start.spring.io/); we have previously covered how to perform this configuration. Here, we will explain the coding process step-by-step.
First, you need to select an LLM (Large Language Model) that Spring AI will use to communicate: Instead of relying solely on an LLM's pre-trained knowledge, RAG fetches relevant context from your own data sources (like databases, PDFs, or internal documentation) at runtime and passes that information along with the user prompt to the LLM.
Step 1: Core Concepts of RAG
- Ingestion & Embedding (Offline / Pre-processing): Raw documents (PDF, TXT, HTML) are read and split into smaller text chunks. An Embedding Model converts these text chunks into numerical vectors. The vectors and text chunks are stored in a Vector Store (e.g., PgVector, ChromaDB, Pinecone, Redis).
- Retrieval (Runtime): When a user submits a query, Spring AI converts the query into a vector and searches the Vector Store for the most semantically relevant document chunks.
- Augmentation & Generation: Spring AI automatically combines the user query and the retrieved documents into an augmented prompt. The augmented prompt is sent to the LLM, which uses the provided context to generate an accurate, hallucination-free answer.
Spring AI simplifies RAG integration through familiar Spring abstractions: DocumentReader & TextSplitter: Interfaces to ingest documents (e.g., using Apache Tika) and break them into processable chunks.
VectorStore: A unified Java abstraction for vector databases (supports pgvector, Redis, Pinecone, Qdrant, Milvus, ChromaDB, etc.).
Advisor API (QuestionAnswerAdvisor): A high-level abstraction that automatically intercepts ChatClient prompts, queries the VectorStore, appends retrieved documents to the prompt context, and passes it to the LLM.
RetrievalAugmentationAdvisor: A modular API for advanced RAG patterns, enabling features like multi-query expansion, document re-ranking, and dynamic metadata filtering.
Step 2: Implementing Basic RAG with Spring AI
In this step, we configure the Spring Boot AI application using Spring Initializr (https://start.spring.io/); we have previously covered how to perform this configuration. Here, we will explain the coding process step-by-step.
Step 2.1: Check the dependencies in the `pom.xml` file and ensure they match your project setup.
Step 2.2: We create a REST controller named `RAGController.java`.
Here, we will see how to implement the LLM packages and classes, and we will also use `@CrossOrigin` to facilitate the design of the web UI.
Step 2.3: We will configure the LLM model settings within the `application.properties` file.
spring.application.name=aiChatclient
server.port=8082
# Use the local Ollama instance for both the LLM and embeddings.
spring.ai.ollama.base-url=http://localhost:11434
spring.ai.ollama.chat.options.model=codellama:latest
spring.ai.ollama.chat.options.num-predict=256
spring.ai.ollama.chat.options.temperature=0.2
spring.ai.ollama.embedding.options.model=mxbai-embed-large:latest
spring.ai.ollama.embedding.enabled=true
# Local knowledge base file used by the RAG controller.
file.path=classpath:data/data.text
Details:
Name: Manoj kumar Vishwakarms
address: 123 Main Street, City, Country
phone: +910000000000
email: manoj@example.com
job: Software Engineer
skills: Java, Spring Boot, SQL, JavaScript
//Something else can also be written in this RAG data file.
How to create an AI chatbot using Spring AI and a Web HTML page.
Spring AI is an open-source application framework designed to easily integrate Artificial Intelligence (AI) features into Spring Boot applications. It functions as a standard middleware layer; rather than training or building AI models from scratch, it enables developers to seamlessly connect their enterprise code with existing AI models.
Below, we outline the step-by-step process for configuring and developing a chatbot.
First, you need to select an LLM (Large Language Model) that Spring AI will use to communicate:
First, you need to select an LLM (Large Language Model) that Spring AI will use to communicate:
Step 1:We will use the standalone Ollama LLM model. To do this, install Ollama on your system (download via https://ollama.com/download/windows)
and then download a free model from https://ollama.com/search.
CMD:
Check Ollama Run using URL: http://localhost:11434/
Step 2:
In this step, we configure the Spring Boot AI application using Spring Initializr (https://start.spring.io/); we have previously covered how to perform this configuration. Here, we will explain the coding process step-by-step.
CMD:
1. widows CMD:
irm https://ollama.com/install.ps1 | iex
2. mocOS CMD:
curl -fsSL https://ollama.com/install.sh | sh
3. Linux CMD:
curl -fsSL https://ollama.com/install.sh | sh
Check Ollama Run using URL: http://localhost:11434/
Step 2:
In this step, we configure the Spring Boot AI application using Spring Initializr (https://start.spring.io/); we have previously covered how to perform this configuration. Here, we will explain the coding process step-by-step.
Step 2.1: Check the dependencies in the `pom.xml` file and ensure they match your project setup.
Step 2.2:
We create a REST controller named `ChatClientController.java`.
Here, we will see how to implement the LLM packages and classes, and we will also use `@CrossOrigin` to facilitate the design of the web UI.
Step 2.3: We will configure the LLM model settings within the `application.properties` file.
spring.application.name=aiChatclient
server.port=8081
spring.ai.ollama.base-url=http://localhost:11434
spring.ai.ollama.chat.options.model=codellama:latest
spring.ai.ollama.chat.options.num-predict=256
spring.ai.ollama.chat.options.temperature=0.2
Step-by-step development video:
How to receive a JWT-based access token from the client, verify the token, and push data using the client's URL?
JWT OAuth2 Integration and JSON Payload Handling in Java: JWT (JSON Web Token) is a token format used in OAuth2.
A JWT is:
- Stateless
- Digitally signed
- Self-contained
Integrating with client APIs using APIs and JSON-based payloads involves an end-to-end process that includes making API calls with JSON payloads and pushing master/other data to REST API endpoints.
############_MK_TOKEN_CLIENT_SECRET_####################
TOKEN_URL=https://a143mk-uat.client.com/api/v1/client/authentication/generate_token
CLIENT_ID=AA143Mkbolgs
CLIENT_SECRET=testa143mk
####Example of Configure URL #############
CUST_URL=https://a143mk-uat.client.com/api/master/push_customer
CUST_USER_PASS_AUTH=useradmin:password //if it is required or not
Step 2: Making an API call with an Json payload and pushing master data to the location.
- A REST API Controller is responsible for handling HTTP requests (such as GET, POST, PUT, DELETE) from clients and routing them to the appropriate service methods. It acts as the entry point for external clients to interact with the backend application.
- Purpose: The main role of the controller is to manage incoming HTTP requests, map them to specific methods (often called endpoints), and return appropriate responses to the client.
- Responsibilities: Handle HTTP requests (e.g., GET, POST, PUT, DELETE). Map the incoming requests to service methods. Return HTTP responses, often in JSON or Json format. Perform basic request validation or authentication. Act as the "interface" between the client and the service layer. In a Spring Boot application, for example, the controller is typically annotated with @RestController and the request mappings are handled using annotations like @GetMapping, @PostMapping, etc.
Example "ClientApiController.java" of a REST Controller in Spring Boot with handlined Json Payload :
The Service class is a part of the business logic layer of your application.
It contains methods that implement the core functionality of the application (e.g., creating, reading, updating, deleting data).
The service class is called by the controller to perform operations that are not directly related to the web request itself.
- Purpose: The service layer acts as a mediator between the controller and the data layer (such as a repository or database). It focuses on business logic and operations.
- Responsibilities: Perform the core business logic of the application. Interact with the database (via repositories or DAOs). Provide methods for the controller to use (i.e., encapsulate business operations). Handle any necessary validation or transformation before sending data back to the controller. In a Spring Boot application, service classes are typically annotated with @Service, and they are injected into the controller using @Autowired (or constructor injection).
Example "CustMastSystemNameService.java" of a Service Class in Spring Boot:
Method Internal Working ->geta143mkCustMasterFOrSYS()
->pusha143mkCustToSystemNameSystem().
Step 3: The authorization server issues an access token in JWT format The client sends this token in requests using
Authorization: Bearer<Token>
The API validates the JWT by checking its signature, expiration, issuer, and audience See the example below for how to obtain an access token for the client: Use this for server-to-server authentication.
The API validates the JWT by checking its signature, expiration, issuer, and audience See the example below for how to obtain an access token for the client: Use this for server-to-server authentication.
Method Internal Working ->geta143mkCustMasterFOrSYS()
->pusha143mkCustToSystemNameSystem().
JWT-based access tokens are secure, stateless, and scalable, making them ideal for modern authentication and authorization systems.
API Integration and XML payload Handling
API integration and XML payload handling in Java using HttpURLConnection
and the Apache HttpClient library. To integrate with a client API using an API and XML-based payload, the entire process includes:
Step 2: Making an API call with an XML payload and pushing master data to the location.
- ClientURLConfig.properties: Used to store client credential details Making an API call with an JSON/XML payload and pushing data communication.
- Data Communication from the two Client API using the JSON/XML payload API.
####Example of Configure URL #############
CUST_URL=https://a143mk.com:443/a143mk1_test/MK/api/init_stage_interface/
CUST_USER_PASS_AUTH=useradmin:password
Step 2: Making an API call with an XML payload and pushing master data to the location.
- A REST API Controller is responsible for handling HTTP requests (such as GET, POST, PUT, DELETE) from clients and routing them to the appropriate service methods. It acts as the entry point for external clients to interact with the backend application.
- Purpose: The main role of the controller is to manage incoming HTTP requests, map them to specific methods (often called endpoints), and return appropriate responses to the client.
- Responsibilities: Handle HTTP requests (e.g., GET, POST, PUT, DELETE). Map the incoming requests to service methods. Return HTTP responses, often in JSON or XML format. Perform basic request validation or authentication. Act as the "interface" between the client and the service layer. In a Spring Boot application, for example, the controller is typically annotated with @RestController and the request mappings are handled using annotations like @GetMapping, @PostMapping, etc.
Example of a REST Controller in Spring Boot with handlined XML Payload :
The Service class is a part of the business logic layer of your application. It contains methods that implement the core functionality of the application (e.g., creating, reading, updating, deleting data). The service class is called by the controller to perform operations that are not directly related to the web request itself.
- Purpose: The service layer acts as a mediator between the controller and the data layer (such as a repository or database). It focuses on business logic and operations.
- Responsibilities: Perform the core business logic of the application. Interact with the database (via repositories or DAOs). Provide methods for the controller to use (i.e., encapsulate business operations). Handle any necessary validation or transformation before sending data back to the controller. In a Spring Boot application, service classes are typically annotated with @Service, and they are injected into the controller using @Autowired (or constructor injection).
Example of a Service Class in Spring Boot:
Method Internal Working ->getAllCustomerStores()->buildCustomerXmlPayload()->pushCustomerXmlToa143mkClient().
To test an API endpoint URL like https://a143mk.com/api/puchCustData/pushCustomerToClient using Postman, refer to the image. This will allow you to verify the API's functionality and inspect the response.
Cross-Origin Resource Sharing
CROSS is a system that allows client web applications (such as JavaScript code) loaded on one domain to interact with resources located on a different domain.
Origin: An "Origin" (or source) URL consists of three parts:
Origin: An "Origin" (or source) URL consists of three parts:
Protocol (scheme): Such as http or https.
Domain (host): Such as a143mk.blogspot.com or localhost.
Port (port number): Such as 8080 or 3000.
If any of these three parts are different in a request, it is called a Cross-Origin request.
Example:
If your frontend (endpoints.com) sends a request to a backend API (api.com), it is Cross-Origin and will be intercepted by the browser. CORS is a way to relax this security restriction in a controlled manner, allowing legitimate cross-origin communication.
Example:
If your frontend (endpoints.com) sends a request to a backend API (api.com), it is Cross-Origin and will be intercepted by the browser. CORS is a way to relax this security restriction in a controlled manner, allowing legitimate cross-origin communication.
Configuring CORS globally in Spring Boot is the preferred approach, as it saves you from having to apply the @CrossOrigin annotation to every controller or method and keeps the configuration centralized.
Example: This method defines global CORS settings
Example: This method defines global CORS settings
- addMapping("/**"): This indicates that the CORS mapping will apply to all paths.
- allowedOrigins: Defines the client origins that are allowed to access your API.
- allowedMethods: The HTTP methods that are allowed.
- allowedHeaders: Allows all headers sent by the client.
- allowedCredentials: Set this to 'true' if the client is using cookies or HTTP authentication.
- maxAge: The time (in seconds) to cache the results of a pre-flight request.
Implementing JWT Token for secure authentication
Implementing JWT (JSON Web Token) in Java typically involves creating a secure authentication
mechanism for your web applications. Below is a basic guide to implement JWT using Java, Spring MVC, and jjwt (a popular Java JWT library).
WorkFlow:
The lifecycle of a JSON Web Token (JWT) typically involves several stages, from creation to expiration and validation. JWTs are widely used for securely transmitting information between parties in the form of a signed and optionally encrypted token. Here’s an overview of the typical lifecycle:
Token Creation
Authentication: When a user logs in, they typically provide credentials (e.g., username and password).
Server Validation: The server validates these credentials (e.g., checks the database for the user’s password).
JWT Creation: If the credentials are correct, the server generates a JWT. The token contains:
Header: Describes the signing algorithm (e.g., HS256, RS256) and token type (JWT).
Payload: Contains the claims. Claims are pieces of information (e.g., user ID, expiration time) that are encoded in the token.
Signature: The header and payload are signed with a secret key (HMAC) or a private key (RSA or ECDSA) to ensure integrity.
Authentication: When a user logs in, they typically provide credentials (e.g., username and password).
Server Validation: The server validates these credentials (e.g., checks the database for the user’s password).
JWT Creation: If the credentials are correct, the server generates a JWT. The token contains:
Header: Describes the signing algorithm (e.g., HS256, RS256) and token type (JWT).
Payload: Contains the claims. Claims are pieces of information (e.g., user ID, expiration time) that are encoded in the token.
Signature: The header and payload are signed with a secret key (HMAC) or a private key (RSA or ECDSA) to ensure integrity.
Download Jar file: jjwt-api-0.10.5.jar
To create a A143mk.JWTAPIConfig, we first need to define a package that will be handled in the configuration.
Create classes name in the A143mk.JWTAPIConfig package.
- JwtRequestFilter
- JwtUtil
- SecurityConfig
- AuthRequest
1. JwtRequestFilter
2.JwtUtil
3. SecurityConfig
4. AuthRequest/PayloderBeanClass
Create a Controller class create a simple controller name is AuthController an endpoint is accessed.
Steps to Test JWT Token in Postman:
Obtain the JWT Token: First, you need to obtain the JWT token from your authentication endpoint. Typically, this is done by making a POST request to your login endpoint with the correct user credentials (username, password, etc.).
2.JwtUtil
3. SecurityConfig
4. AuthRequest/PayloderBeanClass
Create a Controller class create a simple controller name is AuthController an endpoint is accessed.
Steps to Test JWT Token in Postman:
Obtain the JWT Token: First, you need to obtain the JWT token from your authentication endpoint. Typically, this is done by making a POST request to your login endpoint with the correct user credentials (username, password, etc.).
Example (login request):
- Method: POST
- URL: http://localhost:8080/A143mk/api/authenticate
- Body (JSON):
{
"username": "A143mk@Manoj"
}
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJCQVRBQGRtc0Vjb20iLCJpYXQiOjE3NDc5MDc5MzYsImV4cCI6MTc0NzkxMTUzNn0.1eEK4gwwR3mr2bqcIoYYjxwpcTzUKOCtBMH-GBo6X_4
LDAP (Lightweight Directory Access Protocol) authentication in a Spring Boot.
LDAP
(Lightweight Directory Access Protocol) authentication in a Spring Boot application typically involves using Spring Security to configure LDAP authentication properly, ensuring that sensitive data like passwords is protected and communication with the LDAP server is secure.
Here’s a basic guide to securing LDAP authentication in a Spring Boot application:
Add Dependencies:In your pom.xml, add the following dependencies for Spring Security and LDAP:
LDAP Configuration: In your application.properties or application.yml, configure the LDAP server details:
Spring Security Configuration :You can configure Spring Security to authenticate using LDAP by defining a SecurityConfig class.
Here is an example:
Enable Secure LDAP Connections:
If you are using LDAP over TLS/SSL (LDAPS), it’s critical to ensure that your LDAP communication is secured. Change the URL to:
spring.ldap.urls=ldaps://localhost:636
Ensure that your LDAP server supports LDAPS and that proper certificates are installed on the server. If you are using SSL, you can also import the certificate into your Java Keystore (JKS).
Secure Password Handling:In the above configuration, passwords are compared using passwordCompare(). It's recommended to use a hashed password encoder like BCryptPasswordEncoder, which is configured in the example to secure the passwords.
Customizing the Login Page:You can customize your login page if needed by creating a controller for the login and error handling views:
(Lightweight Directory Access Protocol) authentication in a Spring Boot application typically involves using Spring Security to configure LDAP authentication properly, ensuring that sensitive data like passwords is protected and communication with the LDAP server is secure.
Here’s a basic guide to securing LDAP authentication in a Spring Boot application:
Add Dependencies:In your pom.xml, add the following dependencies for Spring Security and LDAP:
LDAP Configuration: In your application.properties or application.yml, configure the LDAP server details:
# application.properties
spring.ldap.urls=ldap://localhost:389
spring.ldap.base=dc=example,dc=com
spring.ldap.username=uid=admin,ou=system
spring.ldap.password=password
spring.ldap.embedded.enabled=false
Spring Security Configuration :You can configure Spring Security to authenticate using LDAP by defining a SecurityConfig class.
Here is an example:
Enable Secure LDAP Connections:
If you are using LDAP over TLS/SSL (LDAPS), it’s critical to ensure that your LDAP communication is secured. Change the URL to:
spring.ldap.urls=ldaps://localhost:636
Ensure that your LDAP server supports LDAPS and that proper certificates are installed on the server. If you are using SSL, you can also import the certificate into your Java Keystore (JKS).
Secure Password Handling:In the above configuration, passwords are compared using passwordCompare(). It's recommended to use a hashed password encoder like BCryptPasswordEncoder, which is configured in the example to secure the passwords.
Customizing the Login Page:You can customize your login page if needed by creating a controller for the login and error handling views:
Role Mapping (Optional):If you want to map roles from LDAP groups or other attributes, you can use LdapAuthoritiesPopulator to fetch roles.
This will ensure the roles are properly populated from LDAP.
Test the Application:Start your Spring Boot application, and it should authenticate users against the LDAP server. Make sure you test with the proper credentials to confirm everything is working securely.
Summary of Key Points:
- LDAP Configuration: Use spring.ldap properties to configure the LDAP server details.
- Spring Security: Configure Spring Security to handle LDAP authentication with ldapAuthentication().
- SSL/TLS: Ensure the LDAP communication is encrypted (use ldaps://).
- Password Encoding: Use a secure password encoder like BCryptPasswordEncoder.
- Role Mapping: Map roles from LDAP as needed using LdapAuthoritiesPopulator. This setup will help you integrate LDAP securely in your Spring Boot application.
Subscribe to:
Posts
(
Atom
)

