RGPD Auth

mp21889d20260218193001

New

GDPR-compliant password reset module for Dolibarr. Replaces the native password forgotten flow with a secure, token-based system.

  • Author Agence 418
  • Module version 1.0
  • Release date 02/18/2026
  • Access to download and updates Lifetime access
  • Compatibility Dolibarr V16 - V23   -   PHP7.1 - 8.4
  • Last update 02/19/2026 09:32 AM

More info...








GDPR-compliant password reset module for Dolibarr. Replaces the native password forgotten flow with a secure, token-based system.















- **Encrypted tokens (AES-256-CBC)**: Tokens are encrypted and embedded in the reset URL. No token stored in the database.







- **Configurable validity**: Set the token expiration duration (default: 1 hour).







- **Custom sender email**: Configure the "From" address or use the Dolibarr default.







- **Anti-enumeration**: Same response whether the user exists or not.







- **Timing attack protection**: Random delay on each request.







- **Password complexity**: Enforces Dolibarr password security rules.







- **Hook integration**: Intercepts Dolibarr's native password forgotten page.



If you think this module is a fork of another one (published after the first one) or violates some terms or conditions of use (for users or vendors), you can make a report at dolistore@dolibarr.org