UniAuth
A Spring Boot starter that puts an internal user store, OAuth2/OpenID Connect, SAML 2.0 and
LDAP behind a single SecurityFilterChain, with a chooser login page offering whichever
mechanisms are switched on.
1. Highlights
-
Four mechanisms, one chain. Adding a second mechanism does not mean a second chain, and local break-glass accounts can sit alongside a directory.
-
No re-declared OAuth2 or SAML configuration. Registrations come from Spring Boot’s own
spring.security.oauth2.client.registration.andspring.security.saml2.relyingparty.. Two lines of standard config are enough to add Google. -
A chooser page driven by real state —
AuthProviderRegistryanswers "what can a user sign in with right now", and the same answer is served as JSON at/uniauth/providers. -
An optional approval gate: authenticating and being admitted are separate decisions, so a provider that will vouch for anyone does not thereby let anyone in.
-
Provider quirks ship as opt-in adapters, never as new mechanisms — GitHub’s second call for an email address, Microsoft’s multi-tenant issuer.
-
Every bean is
@ConditionalOnMissingBean, so an application overrides by declaring its own rather than by excluding the auto-configuration.
2. Install
<dependency>
<groupId>org.alexmond</groupId>
<artifactId>uniauth-spring-boot-starter</artifactId>
<version>4.1.0.3</version>
</dependency>
The starter itself resolves entirely from Maven Central. LDAP and SAML are optional dependencies, added only by applications that use them — which for SAML also spares everyone else the Shibboleth repository, since OpenSAML is not published to Central. See Getting started.
3. Next
-
Getting started — the smallest application that signs somebody in.
-
Mechanisms — what each one is, and the split that governs the chain.
-
Provider recipes — Google, GitHub, Microsoft, and why Apple is unsupported.
-
Approval gate — separating "who are you" from "may you come in".
-
Configuration — every
uniauth.*property. -
Architecture — why one chain, and where the extension points are.
-
API reference: uniauth-spring-boot-starter.