Skip to main content
WebAdmin ships with four authentication modes. Select one with the aseeflow.webadmin.authentication property; each mode activates its own pre-configured Spring Security filter chains for the UI and the REST API.

Choosing a mode

Basic and Form validate credentials against the engine’s Identity Service. OAuth2 and Keycloak delegate authentication to an external identity provider; Keycloak adds an identity provider plugin that synchronizes users and groups into the engine.

Common notes

  • REST security is enabled by default in every mode. Setting aseeflow.webadmin.disable-rest-security: true leaves /engine-rest/** unprotected — only safe when another layer secures it (for example a separate WAR — see Deployment). Understand the consequences first: Never leave the engine REST API unprotected.
  • The required security dependencies are declared as provided in the starter, so you must add them explicitly in your application. Each mode’s page lists what it needs.
  • For OAuth2 and Keycloak, the user-name-attribute and group claim settings are critical — they map identity-provider users and groups onto engine user and group IDs that your authorizations rely on.