Configuration

1. Top level

Property Default What it does

uniauth.enabled

false

Must be set to true. The starter installs nothing unless asked — see below.

uniauth.login-page

/login

The chooser page.

uniauth.default-success-url

/

Where a successful sign-in lands.

uniauth.logout-success-url

/login?logout

Where a sign-out lands.

uniauth.providers-endpoint

/uniauth/providers

JSON list of enabled providers.

uniauth.public-paths

empty

Routes reachable without a session.

The starter already permits its login page, the providers endpoint, /error and the pending page; public-paths is for your own routes.

uniauth.enabled defaults to false. This library decides who may reach what, so being on the classpath is not consent: adding the dependency used to install a catch-all chain in every profile and every test, overriding an application’s own rules before a line of integration was written. The symptom was a broadly-locked application rather than an obviously broken one.

When it does install, it says so once at INFO, naming the default rule and the permitted paths, so an application whose rules stopped applying can find out why from its startup log:

UniAuth installed a SecurityFilterChain: every request needs authentication and approval,
except [/, /how-it-works, /css/**] which are permitted. Providers: [internal, ldap, google].
Set uniauth.enabled=false to back off entirely.

2. Internal store

Property Default What it does

uniauth.internal.enabled

false

uniauth.internal.display-name

Username & password

Label on the chooser.

uniauth.internal.users[].username

uniauth.internal.users[].password

Encoded, with a {noop} or {bcrypt} prefix.

uniauth.internal.users[].roles

[USER]

Without the ROLE_ prefix.

3. LDAP

Needs spring-boot-starter-ldap and spring-security-ldap on the classpath — they are optional dependencies of the starter. See Adding a directory for why.
Property Default What it does

uniauth.ldap.enabled

false

uniauth.ldap.display-name

Directory account

Label on the chooser.

uniauth.ldap.url

Server and base DN, e.g. ldap://host:389/dc=example,dc=com.

uniauth.ldap.user-dn-patterns

[uid={0},ou=people]

Relative to the base DN.

uniauth.ldap.group-search-base

ou=groups

uniauth.ldap.group-search-filter

(member={0})

uniauth.ldap.manager-dn

Bind account for the group search.

uniauth.ldap.manager-password

The context source is qualified as uniAuthLdapContextSource rather than resolved by type, because Boot’s own LdapAutoConfiguration publishes a BaseLdapPathContextSource bound to spring.ldap.*. Without the qualifier a plain @ConditionalOnMissingBean would back off and silently ignore uniauth.ldap.url.

4. OAuth2 / OIDC

Property Default What it does

uniauth.oauth2.enabled

true

Registrations still have to exist.

uniauth.oauth2.github.fetch-email

false

Second call for an address GitHub will not volunteer.

uniauth.oauth2.github.emails-uri

https://api.github.com/user/emails

uniauth.oauth2.microsoft.multi-tenant

false

Tenant-template issuer validation.

Registrations themselves come from Boot: spring.security.oauth2.client.registration. and .provider..

5. SAML 2.0

Needs spring-boot-starter-security-saml2 on the classpath — an optional dependency of the starter, and the one that also obliges a build to declare the Shibboleth repository. See Adding SAML 2.0 for why it is not transitive.

Property

Default

What it does

uniauth.saml.enabled

true

Registrations still have to exist.

Registrations come from spring.security.saml2.relyingparty.registration.*.

6. HTTP Basic

Property Default What it does

uniauth.http-basic.enabled

false

Offers Basic to non-browser callers, over the form-based mechanisms.

uniauth.http-basic.paths

empty

Where the challenge is offered; empty means everywhere. Scopes the challenge, not credential acceptance.

7. Approval gate

Property Default What it does

uniauth.approval.enabled

false

uniauth.approval.require-for

[OAUTH2, SAML, LDAP]

Which mechanisms are held. Internal accounts are excluded by default: writing one into configuration is already an approval.

uniauth.approval.pending-page

/pending

Where a held principal waits.

uniauth.approval.default-roles

[USER]

Granted when an approver approves without naming roles. A federated principal has none of its own.

See the approval gate for the ApprovalStore SPI and why the default implementation is not production-fit.

8. A property trap worth knowing

Binding a list entry from an environment variable replaces the whole collection rather than merging into it, because the higher-priority source wins outright. Supplying only

UNIAUTH_INTERNAL_USERS_0_PASSWORD=…

therefore blanks that entry’s username and roles. When any field of a list entry comes from the environment, supply all of them.