UniAuth

Table of Contents

A Spring Boot starter that puts an internal user store, OAuth2/OpenID Connect, SAML 2.0 and LDAP behind a single SecurityFilterChain, with a chooser login page offering whichever mechanisms are switched on.

1. Highlights

  • Four mechanisms, one chain. Adding a second mechanism does not mean a second chain, and local break-glass accounts can sit alongside a directory.

  • No re-declared OAuth2 or SAML configuration. Registrations come from Spring Boot’s own spring.security.oauth2.client.registration. and spring.security.saml2.relyingparty.. Two lines of standard config are enough to add Google.

  • A chooser page driven by real state — AuthProviderRegistry answers "what can a user sign in with right now", and the same answer is served as JSON at /uniauth/providers.

  • An optional approval gate: authenticating and being admitted are separate decisions, so a provider that will vouch for anyone does not thereby let anyone in.

  • Provider quirks ship as opt-in adapters, never as new mechanisms — GitHub’s second call for an email address, Microsoft’s multi-tenant issuer.

  • Every bean is @ConditionalOnMissingBean, so an application overrides by declaring its own rather than by excluding the auto-configuration.

2. Install

<dependency>
    <groupId>org.alexmond</groupId>
    <artifactId>uniauth-spring-boot-starter</artifactId>
    <version>4.1.0.3</version>
</dependency>

The starter itself resolves entirely from Maven Central. LDAP and SAML are optional dependencies, added only by applications that use them — which for SAML also spares everyone else the Shibboleth repository, since OpenSAML is not published to Central. See Getting started.

3. Next