This guide provides comprehensive information about security-related configuration options in EvTrack, including SAML SSO setup and endpoint access control through security hardening properties.

SAML SSO Configuration

For detailed SAML Single Sign-On configuration with Azure Entra ID, refer to the comprehensive guide:

  • KB Article: SAML SSO Configuration Guide
  • Reply URL: https://FQDN/login/saml2/sso/entra
  • Entity ID: evtrack-visitor-management
  • Login Page: When SSO is enabled, users are directed to /login/sso which displays the SAML login button

Endpoint Access Control

EvTrack provides fine-grained control over API endpoints through configuration properties. This allows administrators to enable or disable specific features based on security requirements.

1. Password Reset Endpoints - Disabled when SSO is enabled

  • Property: evtrack.security.config.sso.enable=true disables password reset functionality
  • Endpoint path: /auth/password-reset/**
  • Note: When SSO is enabled, password reset functionality is automatically disabled

2. FondVision WS Endpoint - Disabled by default

  • Property: evtrack.security.config.hardening.fond-vision-ws.enabled=false (default)
  • Endpoint path: /qa/mcardsea.php
  • To enable: Set evtrack.security.config.hardening.fond-vision-ws.enabled=true

3. Akuvox WS Endpoints - Disabled by default

  • Property: evtrack.security.config.hardening.akuvox-ws.enabled=false (default)
  • Endpoint path: /api/device/akuvox/v1/**
  • To enable: Set evtrack.security.config.hardening.akuvox-ws.enabled=true

4. Onsite API Endpoints - Disabled by default

  • Property: evtrack.security.config.hardening.onsite-api.enabled=false (default)
  • Endpoint paths: /api/onsite/v1/**
  • To enable: Set evtrack.security.config.hardening.onsite-api.enabled=true

5. Axis WS ACAP Endpoints - Disabled by default

  • Property: evtrack.security.config.hardening.axis-ws.enabled=false (default)
  • Endpoint path: /api/device/axis/ws/v1/**
  • To enable: Set evtrack.security.config.hardening.axis-ws.enabled=true

6. Axis Barcode ACAP Endpoints - Disabled by default

  • Property: evtrack.security.config.hardening.axis-barcode.enabled=false (default)
  • Endpoint path: /api/device/axis/barcode/v1/**
  • To enable: Set evtrack.security.config.hardening.axis-barcode.enabled=true

7. Wix Booking API Endpoints - Disabled by default

  • Property: evtrack.security.config.hardening.wix-api.enabled=false (default)
  • Endpoint path: /api/wix/v1/booking/**
  • To enable: Set evtrack.security.config.hardening.wix-api.enabled=true

8. Connect App API Endpoints - Disabled by default

  • Property: evtrack.security.config.hardening.connect-app-api.enabled=false (default)
  • Endpoint paths: /api/app/v1/**
  • To enable: Set evtrack.security.config.hardening.connect-app-api.enabled=true
  • Covers: the Connect mobile app’s authentication, profile, credential, document, invite, notification, event, upload, visitor and site-booking endpoints

9. Guard API Endpoints - Enabled by default

  • Property: evtrack.security.config.hardening.guard-api.enabled=true (default)
  • Endpoint paths: /api/** and /api/v1/**
  • Note: Enabled by default for backward compatibility
  • To disable: Set evtrack.security.config.hardening.guard-api.enabled=false
  • Covers: guard app authentication and operational endpoints

10. Kiosk API Endpoints - Enabled by default

  • Property: evtrack.security.config.hardening.kiosk-api.enabled=true (default)
  • Endpoint paths: /api/kiosk/v1/**
  • Note: Enabled by default for backward compatibility
  • To disable: Set evtrack.security.config.hardening.kiosk-api.enabled=false
  • Covers: kiosk authentication and operational endpoints

11. Driver Subsystem RPC Endpoint - Disabled by default

  • Property: evtrack.security.config.hardening.driver-subsystem.enabled=false (default)
  • Endpoint path: /api/rpc/v1/driver/**
  • To enable: Set evtrack.security.config.hardening.driver-subsystem.enabled=true
  • Purpose: Handles driver subsystem RPC messages and commands

12. Web Service API Localhost-Only Access

  • Property: evtrack.security.config.hardening.webservice-api.restrict-to-localhost=false (default)
  • Affected paths: /api/ws/** and /api/onsite/** (GET, POST, PUT, DELETE)
  • Special behavior: When EVTRACK_LIC environment variable is present and property is not explicitly set, defaults to true
  • Allowed connections when restricted:
    • IPv4: 127.0.0.1
    • IPv6: 0:0:0:0:0:0:0:1 or ::1
  • Authentication: Uses JWT authentication for localhost connections

Configuration Best Practices

  1. Security Hardening: By default, most device-specific and third-party integration APIs are disabled. Enable only the endpoints required for your specific deployment.

  2. SSO Integration: When SSO is enabled, ensure that password reset functionality is properly disabled to maintain security integrity.

  3. API Access: Consider the security implications before enabling any disabled-by-default API endpoints. Each should be enabled only if there’s a specific business requirement.

  4. Localhost Restrictions: The Web Service API can be restricted to localhost-only access for enhanced security, particularly useful in production environments with the EVTRACK_LIC environment variable.


Back to top

Copyright EvTrack. All rights reserved.

Page last modified: 2026-09-28 15:32.