Promotions

  • Interview

    This module allows you to create questionnaires in Dolibarr. This module can be used alone but can also be added to the Agefodd module. (It is integrated into the Agefodd 2025 version).

    250.00 €  (600€)
  • Remindme: Automatic reminder (email, event, notification)

    Allows you to program different types of reminders based on a trigger. RemindMe is here for you!

    280.00 €

New products

SmartAuth 2.0.54 (V18 - V23)

mp1287d20250924161817

Authentication server for Dolibarr: JWT tokens for mobile apps, OAuth2/OpenID Connect provider, single sign-on and machine-to-machine access.

  • Author CAP-REL
  • Module version 2.0.54
  • Release date 09/24/2025
  • Access to download and updates Lifetime access

More info...

Your mobile apps, websites and online services need to know who is signing in and what they are allowed to do. SmartAuth turns your Dolibarr into the identity server of all of them: accounts, rights and revocations stay in your ERP, and no third-party service ever holds your users' passwords.

Mobile apps

  • JWT access and refresh tokens, rotated on every use
  • One device, one token family: losing a phone only cuts off that phone
  • QR code pairing: scan the Dolibarr screen, no password typed on the phone
  • Offline synchronisation of Dolibarr objects, with conflict detection
  • Browser push notifications, without any third-party subscription

OAuth2 and OpenID Connect identity provider

  • Single sign-on for WordPress, Nextcloud and any OpenID Connect application
  • Single sign-on to the Dolibarr back office itself
  • Authorization code with PKCE, consent screen, automatic discovery
  • Portal accounts, members and internal users, each enabled separately
  • Machine-to-machine access (client credentials) for your services and scripts

Security and monitoring

  • Sign-in attempts throttled per address and per login
  • E-mail alert on a sign-in from an unknown device or address
  • Sign-in log, device list and revocation from the user card
  • Administration pages restricted by right and by entity

For developers

  • REST API on Dolibarr objects, bounded by the rights of the signed-in user
  • Routes declared by your own modules, protected by JWT or OAuth2 tokens
  • File uploads and self-service registration for your applications

Requirements

  • Dolibarr 18.0 or later, PHP 7.4 or later
  • PHP openssl extension
  • An HTTPS address for Dolibarr, required by OAuth2 and the mobile apps

Every feature is described in the online documentation: doc.cap-rel.fr/smartauth

What the purchase covers

  • The module, and access to its updates for the period stated on this sheet
  • Bug fixes, including the ones you report
  • An email on every new release

To be told automatically about new versions, of this module and of the Dolibarr ecosystem at large, subscribe on dolinews.com: that is where our release announcements are published.

Support

Support goes through our support form, not through the comments on this sheet.

Support is not free. You want competent people on the other side: it is fair that they are paid for that time. The price shown covers the module and its updates. It covers neither installing nor configuring your Dolibarr, nor training your teams, nor specific developments, nor investigating an environment we do not host.

A reproducible bug in the module is fixed at no charge, as part of the updates above.

Before buying

  • Check the Dolibarr and PHP versions stated at the top of this sheet: beyond them, the module is not tested
  • Modules are deployed from Home > Setup > Modules > Deploy an external module, which requires an active custom directory on your installation
  • When a module relies on an online service, the subscription to that service is separate from buying the module, and is stated above

Publisher

Module developed by CAP-REL, under the GPL-3.0-or-later licence. Online documentation at doc.cap-rel.fr.

Version history

2.0.54 -- 20261007

  • Stop answering any origin with credentials in CORS outside the API router
  • Require the read right and scope the dashboard, logs and push logs to the entity
  • Restrict token, device and log pages to their owner, admins and the current entity
  • Check the CSRF token on token revoke, delete and rename links and on setup links
  • Fix stored XSS in the token history and device details of the user tab
  • Revalidate the OAuth2 service user status and entity on every M2M call
  • Keep reserved payload keys out of reach of the request body
  • Apply mapper visibility rules to sync pull, push and conflict resolution
  • Never store or return secret columns in sync conflicts
  • Check Dolibarr document access rules on every listed or downloaded document
  • Revoke OAuth2 sessions on every password reset
  • Revoke mobile sessions and anonymise contact and thirdparty on account self-deletion
  • Throttle alternative e-mail requests and require a consent for the client
  • Reject redirect targets that browsers turn into protocol-relative URLs
  • Strip JavaScript from account page sections provided by other modules
  • Escape stored extrafield values in sellist label lookups
  • Lock SSO logins per address and per login with a login-wide ceiling
  • Verify user passwords against every Dolibarr hash format
  • Check typ, kid and issuer on session cookies and logout hints
  • Refuse mixed client authentication methods on the OAuth2 token endpoint
  • Serialise self-service registrations per address and refuse taken logins
  • Log out other sessions when the password is changed from the account page
  • Consume the reset token before writing the new password
  • Keep uploads and temp files under the module data root and escape download names
  • Keep a single Content-Security-Policy on the OAuth portal
  • Hide the token salt from every screen
  • Cancel the tokens and families of a deleted device
  • Refuse toggling or deleting an OAuth client of another entity
  • Escape LIKE wildcards in list searches and text filters
  • Admit internal users at the SSO login, as the Dolibarr back office SSO requires
  • Make the Dolibarr back office SSO callback reach the SmartAuth login handler
  • Show members correctly on the OAuth consent page
  • Stop the login loop when an application asks for prompt=login
  • Answer invalid_grant instead of a server error when a refresh token rotation races
  • Answer 500 instead of an empty token when token storage fails
  • Refuse to issue tokens when their device family cannot be created
  • Show the token revocation message on the OAuth logout page
  • List every OAuth client when no status filter is chosen
  • Restore the global search field of the token, log and device lists
  • Restore the application list on MySQL with ONLY_FULL_GROUP_BY
  • Fix fatal errors on category sellists, smart extrafields and links without mapper
  • Export extrafields holding 0 and keep mapper labels free of HTML entities
  • Report malformed sync changes per entry and detect delete conflicts
  • Send push notifications to recipients by entity and group rights
  • Keep the port in the VAPID audience and restrict push urgency to RFC 8030 values
  • Let admins purge the push send journal
  • Replace the route cache atomically and skip broken route files
  • Enable the cleanup job on module activation
  • Store token renames in the device label
  • Index token lookup columns and widen logged IP addresses for IPv6
  • Restore French accents and align translations without overriding core keys
  • Use Dolibarr pictos instead of emojis

2.0.52 -- 20260925

  • password reset now goes through the Dolibarr object
  • the legacy clear-text password column is cleared on reset
  • live sessions of both linked identities are revoked on reset
  • ship composer.lock
  • update phpunit to 9.6.37 (development dependency)
  • a device whose reference could not be computed
  • photo extrafield on an object with no storage path no longer builds a path
  • missing numbering addon is reported again
  • SSO login on a multi-entity instance no longer dies
  • the last-cleanup and JWT key rows are written again
  • the attached-files counter no longer counts .meta files and thumbnails
  • the sync push survives a Dolibarr method declaring a union type
  • ids and paging values read from the request are cast
  • category extrafields no longer break on Dolibarr 23
  • the dashboard no longer passes an array where llxHeader expects
  • object creation, update and deletion pass the trigger flag
  • static analysis raised from level 1 to level 6

2.0.50 -- 20260922

  • cleanup module builder stuff on admin
  • update phpstan stuff and gitlab for CI
  • move code coverage to a specific config file

2.0.46 -- 20260922

  • record whether the PWA runs installed on each logical user device
  • new manifest
  • route cache: fix the logging
  • route cache: the legacy filesystem scan
  • dmTrait resolves rowid through $id when the Dolibarr class has no $fields
  • OAuth setup forms guarded against double submit
  • memcached is flushed last in the module init
  • announced baseline aligned on Dolibarr 18.0 and PHP 7.4
  • drop the dead v16 FormSetup backport
  • module files are included through dol_include_once
  • cleanup module builder stuff
  • HTTP test suite covers every admin and list page against fatal errors

2.0.44 -- 20260917

  • photo annotations: access follows the owning module, not only the uploader
  • AnnotationsHelper::get/set delegate to the smartmaker_canAccessAnnotations hook
  • default stays deny, so modules implementing nothing keep the previous behaviour

2.0.42 -- 20260907

  • user tab: scope both lists to the displayed user
  • an admin was served every token of every user
  • user tab: entity filter on tokens and logs
  • user tab: keep the user id on ?userid= entry
  • user tab: token activity history endpoint was missing
  • user tab: fix ambiguous ORDER BY hiding both lists
  • RSA key generation no longer depends on host openssl.cnf
  • broken host openssl.cnf took the whole IdP down
  • test harness: HTTP suite for server-rendered Dolibarr pages
  • test harness: per-user temp document directory

2.0.40 -- 20260827

  • (2026 summer sprint)
  • generic REST facade objects/{objtype}
  • document line facade (add/update/delete/reorder) for order/invoice/proposal
  • document workflow actions (validate/setDraft/close/setPaid/...)
  • invoice payment facade (record/list payments)
  • CrudInvoker handles delete($rowid, $user) and classes without update()
  • supplier document lines/actions/payments
  • contract lines through the facade
  • extra update-side guards on the facade
  • sync push writes the extrafields mapper
  • fix sync push erasing the extrafields a partial payload
  • SMARTAUTH_FACADE_TYPES restricts which registry types objects/* serves on an
  • instance (CSV, empty = every type); a closed type answers like an unknown one
  • reject a JWT whose login claim now resolves to another user than its signed
  • oauth logout (RP-initiated)
  • sync register refuses (409)
  • sync conflict detection
  • sync delete: the tombstone is only created after a successful delete
  • sync raw fallback
  • sync push batches are capped (500 changes, SMARTAUTH_SYNC_PUSH_MAX_CHANGES)
  • the admin "require PKCE" toggle is now enforced
  • /refresh is rate limited per IP
  • the English password reset email body carried no %s placeholders
  • texts injected into JavaScript use transnoentities()
  • duplicate keys removed from the French lang file
  • double-submit guard (data-submit-once)
  • web push spec aligned on the shipped constant

2.0.38 -- 20260724

  • new option to disable force update password on first login
  • generic rest facade for common objects

2.0.36 -- 20260715

  • new option to get only thumbnails on request for local cache / offline
  • add entity on auth
  • cleanup warehouses code
  • trait base / dmtrait
  • add crud on base objects
  • better sync algo

2.0.34 -- 20260702

  • update add sync process regarding smartpos needs
  • add cursor for sync partial data on big database

2.0.32 -- 20260629

  • better idempotency for synced data
  • add cache for fk_keys (dolmapping)

2.0.30 -- 20260619

  • unify logs with common prefix
  • fix route and route cache for modules who commes with front react plugins
  • add more extrafields support on auto mapping system
  • add missing extrafields "list" properties (visible)
  • add "my" devices on relogin on front app

2.0.28 -- 20260617

  • better route cache support and update
  • add webpush stuff
  • better logs collect
  • policy : checkuser rights & passwords
  • update user doc
  • add more defensive code on oauth
  • better protection on spoofing tips
  • add security checks on controllers
  • user can delete / revoke own devices
  • do not hardcode custom anymore for custom dolibarr setup

2.0.22 -- 20260603

  • Add webpush subsystem for notificaitons on PWA
  • Add sso portal
  • Better log collect

2.0.21 -- 20260526

  • TokenService now scopes its JTI and access-token lookups by entity
  • RevokedJtiController caps the ?since= parameter length to 20 chars
  • Add viewport_mode column to llx_smartauth_user_devices
  • Handle viewport-mode (smartphone / tablet / desktop)

2.0.20 -- 20260521

  • Missing public folder
  • Product / Services mapping
  • Handle "" and zero values

2.0.18 -- 20260520

  • Mappers Dolibarr -> API
  • Next step for dolMapping objects
  • Include dolMapping of dictionaries
  • Handle extrafields
  • Add tests coverage
  • OAuth2 hook smartmaker_oauth_pre_token
  • TokenService::createAccessToken
  • TokenController propagates the harvested extra_claims
  • JWT revocation list
  • ResponseTrait gains sendJsonResponseWithHeaders() and sendNotModified()

2.0.16 -- 20260513

  • Add Idempotency-Key support on POST /upload (replays the 2xx response on retry instead of creating duplicate files when the PWA loses the network mid-upload). New table llx_smartauth_upload_idempotency with auto-purge in doScheduledJob (24h for completed, 10min for stale processing). Backend contract for the smartcommon useUploadQueue hook (cf documentation/SPEC_UPLOAD_IDEMPOTENCY.md).
  • Test harness: cleanSmartAuthTables() now discovers smartauth tables at runtime via sqlite_master / SHOW TABLES, no more hard-coded list to maintain.

2.0.14 -- 20260507

  • Full security review
  • Add oAuth stuff for sso

2.0.12 -- 20260428

  • Fix sanitizeRequestData : call loadExternalSchemas for external specs like photo uploads
  • Add binary upload stuff

2.0.10 -- 20260413

  • Fix all includes to use dol_include_once()
  • Add Memcached cache flush on module activation/upgrade
  • Rewrite About page: module info, feedback form, donation box, useful links, changelog display
  • Add admin CSS (css/admin.css.php) for About page layout
  • Set $help_url to https://doc.cap-rel.fr/smartauth/
  • Normalize all dol_syslog() calls with consistent "SmartAuth" prefix
  • Add missing translation keys for en_US (dashboard, user tab, OAuth, GeoIP, about page)
  • Fix missing French accents in OAuth and Dolibarr Integration translation keys

2.0.8 -- 20260303

  • add auth solution for m2m

2.0.7 -- 20260302

  • use hash share for downloads
  • add entries into ecm database if missing
  • add batch queries on documents index

2.0.5 -- 20260219

  • better tests coverage, fix bugs thanks to tests
  • fix mapping object for dolibarr like Thirdparty / Societe
  • add categories in list of objectTypeConfig
  • add catagories linked to an object

2.0.2 -- 20260218

  • dynamic manifest file - you can choose your icon and name (install app icon on desktop)
  • new offline sync system for binary files (pdf / others)

2.0.1 -- 20260210

  • oAuth2 server working with wordpress client as POC

2.0.0 -- 20260209

  • Full oAuth2 identity provider solution

1.1.2 -- 20260201

  • Add more tools for offline mode
  • Add LocalRoute system

1.1.0 -- 20260123

  • Major version
  • Auto build cache router and auto detect invalidate cache if routes changed
  • Add full CORS support
  • Fix GeoIP auto setup
  • Add PATCH support to router

1.0.16 -- 20251227

  • Fix null pointer in RateLimiter when fetch_object returns null
  • Fix undefined array keys in dmTrait and class files
  • Fix handling of non-present properties in $fields of core Dolibarr objects
  • Fix date_creation in smartlogs class
  • Fix decoded token handling in AuthController
  • Fix logs creation when user does not exist in table
  • AuthController now returns complete smartauth object with token and decoded data
  • Add status check in AuthController
  • Remove Kanban mode from list views
  • Improve test coverage with new integration tests
  • Optimize test performance with SQLite in RAM
  • Improve GitLab CI pipeline

1.0.14 -- 20251216

  • new mapping for near than all dolibarr objects
  • change naming to be as close as possible to dolibarr main api
  • new documentation
  • add an api naming convention document (rules)
  • update existing objects to apply that convention

1.0.12 -- 20251203

  • get real ip in case of proxy
  • better refresh token
  • add gps data on llx_ecm_files
  • add device_id entry
  • disable mass actions
  • use cache on get device id
  • add new route for devices
  • better next num ref for dolibarr object ref
  • fix refresh token process

1.0.10 -- 20251113

  • Auto-Install GeoIP database
  • Change ping to refresh route
  • Check refresh token
  • Optimize companies logo size
  • SmartObject type
  • SmartFileController (maybe, POC to become or not)
  • Get metadata from ECM database for files

1.0.8 -- 20251103

  • New dashboard on index
  • New user page for token list (experimental)
  • Switch to two token (access & refresh)
  • Code factoring
  • Update cron job
  • Fix for better security
  • Code cleanup
  • Use cache and new Rate Limiter
  • Better dolibarr < 18 compat'
  • Change photo and other special fields to smart* (prefix)
  • Fix options and extrafields
  • New multicompany support

1.0.5 -- 20251028

  • Fix MultiCompany errors
  • Fix extrafields without complete definition
  • Use const names (better than integer hardcoded)

1.0.4 -- 20250930

  • Add compressOptions to photo objects

1.0.2 -- 20250924

  • Firs public beta release

1.0.1 -- 20250416

  • Better payload args passed to functions
  • New dolibarrMapping classes

For older releases, back to the first publication on 2024-04-04, see the full changelog on the "About" page of the module once it is installed.




If you think this module is a fork of another one (published after the first one) or violates some terms or conditions of use (for users or vendors), you can make a report at dolistore@dolibarr.org