Skip to main content
WebAdmin is configured through application.yaml (or application.properties) under the aseeflow.webadmin prefix, using Spring Boot’s externalized configuration. This page lists the core properties that apply to every authentication mode. For provider-specific settings, see Authentication.

Core properties

Do not use an empty base-path in a standalone Spring Boot application — it causes security conflicts with Swagger and the legacy web apps. Use a dedicated path such as webadmin or admin. The empty value is for WAR deployments only (see Deployment).
Turning off REST security (disable-rest-security: true) leaves the engine REST API open — in a standalone Spring Boot application every /engine-rest/** request then succeeds with no credentials. Only do this when REST is secured by another layer. See Never leave the engine REST API unprotected.

Examples

Default base path:
Custom base path:
Hide Swagger and the legacy app links:
Enable the Engine REST proxy (for OAuth2 token forwarding):

The Engine REST proxy

By default the browser calls the engine REST API directly. Enabling the proxy routes those calls through WebAdmin (/{base-path}/api/engine-rest/**), which then forwards them to engine-rest-server-url on the same server. The proxy’s main purpose is to propagate the OAuth2 access token from the WebAdmin session to the engine REST API — required when REST and WebAdmin are deployed as separate WARs under OAuth2 or Keycloak. For Basic and Form authentication, direct calls work and the proxy can stay disabled.