Configuration
1. Top level
| Property | Default | What it does |
|---|---|---|
|
|
Must be set to |
|
|
The chooser page. |
|
|
Where a successful sign-in lands. |
|
|
Where a sign-out lands. |
|
|
JSON list of enabled providers. |
|
empty |
Routes reachable without a session. |
The starter already permits its login page, the providers endpoint, /error and the pending
page; public-paths is for your own routes.
|
When it does install, it says so once at INFO, naming the default rule and the permitted paths, so an application whose rules stopped applying can find out why from its startup log:
|
2. Internal store
| Property | Default | What it does |
|---|---|---|
|
|
|
|
|
Label on the chooser. |
|
||
|
Encoded, with a |
|
|
|
Without the |
3. LDAP
Needs spring-boot-starter-ldap and spring-security-ldap on the classpath — they are
optional dependencies of the starter. See Adding
a directory for why.
|
| Property | Default | What it does |
|---|---|---|
|
|
|
|
|
Label on the chooser. |
|
Server and base DN, e.g. |
|
|
|
Relative to the base DN. |
|
|
|
|
|
|
|
Bind account for the group search. |
|
|
The context source is qualified as uniAuthLdapContextSource rather than resolved by type,
because Boot’s own LdapAutoConfiguration publishes a BaseLdapPathContextSource bound to
spring.ldap.*. Without the qualifier a plain @ConditionalOnMissingBean would back off and
silently ignore uniauth.ldap.url.
4. OAuth2 / OIDC
| Property | Default | What it does |
|---|---|---|
|
|
Registrations still have to exist. |
|
|
Second call for an address GitHub will not volunteer. |
|
||
|
|
Tenant-template issuer validation. |
Registrations themselves come from Boot:
spring.security.oauth2.client.registration. and .provider..
5. SAML 2.0
Needs spring-boot-starter-security-saml2 on the classpath — an optional dependency of
the starter, and the one that also obliges a build to declare the Shibboleth repository. See
Adding SAML 2.0 for why it is not transitive.
|
Property |
Default |
What it does |
|
|
Registrations still have to exist. |
Registrations come from spring.security.saml2.relyingparty.registration.*.
6. HTTP Basic
| Property | Default | What it does |
|---|---|---|
|
|
Offers Basic to non-browser callers, over the form-based mechanisms. |
|
empty |
Where the challenge is offered; empty means everywhere. Scopes the challenge, not credential acceptance. |
7. Approval gate
| Property | Default | What it does |
|---|---|---|
|
|
|
|
|
Which mechanisms are held. Internal accounts are excluded by default: writing one into configuration is already an approval. |
|
|
Where a held principal waits. |
|
|
Granted when an approver approves without naming roles. A federated principal has none of its own. |
See the approval gate for the ApprovalStore SPI and why the default
implementation is not production-fit.
8. A property trap worth knowing
Binding a list entry from an environment variable replaces the whole collection rather than merging into it, because the higher-priority source wins outright. Supplying only
UNIAUTH_INTERNAL_USERS_0_PASSWORD=…
therefore blanks that entry’s username and roles. When any field of a list entry comes from the environment, supply all of them.