Add-on Directory

AppJars User Manager - Vaadin Add-on Directory

Users, roles, groups and runtime access rules for Vaadin apps: secure Spring Security login, invite and reset links, and optional Google or GitHub sign-in. Commercial AppJar with a free mode. AppJars User Manager - Vaadin Add-on Directory
> **Licensing:** this add-on is a thin wrapper licensed under **Apache 2.0**. It contains no code of its own and simply pulls in the **User Manager AppJar** modules, which are **commercial software** distributed under the [AppJars Software License Agreement](https://www.appjars.com/legal/license/v1/). You can use User Manager for free in **free mode** (up to 5 users; once reached, the management views lock until users are deleted). A license removes all limits. See [Licensing](https://docs.appjars.com/licensing/). **User Manager** provides complete authentication and authorization management for Vaadin applications, with an administration UI built with Vaadin Flow and backed by Spring Security. Manage users, roles and groups, onboard users through secure links, and let administrators change who can reach each view at runtime, without touching the code. ## Features - **Users, roles and groups:** assign roles directly or bundle them into *groups*; users inherit every role of their groups, and `@RolesAllowed` respects the result. - **Runtime access rules:** prioritized rules grant or deny access to views matched by path, prefix, suffix, substring or regular expression; unmatched views fall back to your security annotations. - **Link-based onboarding:** instead of open self-registration, administrators generate time-limited registration links and share them through any channel. - **Pre-configured registration:** registration links created from a group or role add the new user to it automatically on signup. - **Secure password reset:** administrators issue expiring reset links instead of sending temporary passwords, and signed-in users can change their own password. - **External authentication:** sign in with Google or GitHub over OAuth2 / OpenID Connect, configured at runtime, with an SPI for custom providers such as Vaadin SSO Kit. ## Installation If your project doesn't declare it yet, add the Vaadin add-ons repository: ```xml vaadin-addons https://maven.vaadin.com/vaadin-addons ``` Add the dependency. The wrapper declares the AppJars repository (`https://maven.appjars.com`), so Maven resolves the modules automatically: ```xml org.vaadin.addons.appjars appjars-user-manager 2.0.2 ``` - **Gradle** ignores repositories declared in dependency POMs, so add `maven { url "https://maven.appjars.com" }` to your repositories. - **Nexus/Artifactory mirroring everything (`mirrorOf *`):** your administrator needs to add a proxy for `https://maven.appjars.com`. Then follow the [Getting started guide](https://docs.appjars.com/user-manager/getting-started/). ## Requirements - Java 21 - Vaadin 25.2 - Spring Boot 4.1 - Spring Security, configured with User Manager's navigation access checker and Remember Me services ([details](https://docs.appjars.com/user-manager/getting-started/)) - JPA / Hibernate - Spring Boot OAuth2 client, only if you enable external authentication providers ## Included dependencies | Artifact | License | |---|---| | `com.appjars:appjars-user-manager-flow` | AppJars Software License Agreement v1 (commercial) | | `com.appjars:appjars-user-manager-business-impl` | AppJars Software License Agreement v1 (commercial) | | `com.appjars:appjars-user-manager-data-impl` | AppJars Software License Agreement v1 (commercial) | These modules transitively bring in the rest of the User Manager modules and `appjars-*-utils` (same commercial license), plus open-source libraries such as Vaadin add-ons by Flowing Code (Apache 2.0). ## Links - [Product page](https://www.appjars.com/catalog/user-manager/) - [Documentation](https://docs.appjars.com/user-manager/overview/) - [Demo application](https://github.com/AppJars/user-manager-demo) - [Licensing and free mode](https://docs.appjars.com/licensing/) AppJars are built and maintained by [Flowing Code](https://www.flowingcode.com).
Author Homepage
Discussion Forum
View on GitHub
Online Demo
Issue tracker

AppJars User Manager version 2.0.2
A patch release, with a fix for anonymous access on existing installations. #### Fixes - **Concurrent first visitors** are no longer bounced to the login when User Manager is adopted over an existing user table: the anonymous authority is now created at startup instead of on the first anonymous navigation.