aseeflow.webadmin.authentication property; each mode activates its own pre-configured Spring Security filter chains for the UI and the REST API.
Choosing a mode
Basic and Form validate credentials against the engine’s Identity Service. OAuth2 and Keycloak delegate authentication to an external identity provider; Keycloak adds an identity provider plugin that synchronizes users and groups into the engine.
Common notes
- REST security is enabled by default in every mode. Setting
aseeflow.webadmin.disable-rest-security: trueleaves/engine-rest/**unprotected — only safe when another layer secures it (for example a separate WAR — see Deployment). Understand the consequences first: Never leave the engine REST API unprotected. - The required security dependencies are declared as
providedin the starter, so you must add them explicitly in your application. Each mode’s page lists what it needs. - For OAuth2 and Keycloak, the
user-name-attributeand group claim settings are critical — they map identity-provider users and groups onto engine user and group IDs that your authorizations rely on.