I think the best way to doing server side authorization is JAAS (Java Authentication and Authorization Service). The service support by spring and you have not any consider about authorization.