Skip to main content
Form-based authentication replaces the browser’s Basic dialog with a custom, branded login page. Credentials are validated against the ASEE Flow engine’s Identity Service.

Dependency

This dependency is provided in the starter, so include it explicitly.

Configuration

How it works

Unauthenticated users are redirected to the custom login page at /aseeflow-login.html. Credentials are submitted to /webadmin-login; a successful login redirects to /webadmin, and a failed one returns to /aseeflow-login.html?error. Two separate filter chains are used — one for the WebAdmin UI (form login) and one for the REST API. The login page, its logo, and the login endpoint are reachable anonymously; everything else under the base path requires authentication. REST endpoints (/engine-rest/**) are protected by default and return 401 when unauthenticated; since 1.0.2 they accept the login session and HTTP Basic, so programs can call them too. Set disable-rest-security: true to disable — only when REST is secured elsewhere (consequences). Logout invalidates the session and returns to the login page.

When to use it

Form authentication suits production web applications that want a user-friendly, branded login, and internal portals where users expect a traditional web login. It is also easy to swap for enterprise SSO (OAuth2 or Keycloak) later. It needs WebAdmin to serve the engine REST API itself — your Spring Boot application or ASEE Flow Run. On the Tomcat and WildFly distributions the REST API is a separate WAR that doesn’t know WebAdmin’s session: once you protect it, use basic, oauth2 or keycloak there (Production hardening).

Properties