Nuevos productos

SmartAuth 2.0.54 (V18 - V23)

mp1287d20250924161817

Servidor de autenticación para Dolibarr: tokens JWT para aplicaciones móviles, proveedor OAuth2/OpenID Connect, inicio de sesión único y acceso máquina a máquina.

  • Autor CAP-REL
  • Versión del módulo 2.0.54
  • Fecha de lanzamiento 24/09/2025
  • Acceso a actualizaciones y descargas Acceso de por vida

Más información...

Sus aplicaciones móviles, sitios web y servicios en línea necesitan saber quién se conecta y a qué tiene derecho. SmartAuth convierte su Dolibarr en el servidor de identidad de todos ellos: las cuentas, los permisos y las revocaciones permanecen en su ERP, y ningún servicio de terceros guarda jamás las contraseñas de sus usuarios.

Aplicaciones móviles

  • Tokens JWT de acceso y de actualización, renovados en cada uso
  • Un dispositivo, una familia de tokens: perder un teléfono solo desconecta ese teléfono
  • Emparejamiento por código QR: se escanea la pantalla de Dolibarr, sin escribir contraseña en el móvil
  • Sincronización sin conexión de los objetos de Dolibarr, con detección de conflictos
  • Notificaciones push en el navegador, sin suscripción a servicios de terceros

Proveedor de identidad OAuth2 y OpenID Connect

  • Inicio de sesión único para WordPress, Nextcloud y cualquier aplicación compatible con OpenID Connect
  • Inicio de sesión único en el propio back-office de Dolibarr
  • Código de autorización con PKCE, pantalla de consentimiento, descubrimiento automático
  • Cuentas de portal, miembros y usuarios internos, activables por separado
  • Acceso máquina a máquina (client credentials) para sus servicios y scripts

Seguridad y seguimiento

  • Limitación de los intentos de conexión por dirección y por identificador
  • Alerta por correo electrónico ante una conexión desde un dispositivo o una dirección desconocidos
  • Registro de conexiones, lista de dispositivos y revocación desde la ficha del usuario
  • Páginas de administración restringidas por permiso y por entidad

Para desarrolladores

  • API REST sobre los objetos de Dolibarr, limitada por los permisos del usuario conectado
  • Rutas declaradas por sus propios módulos, protegidas por token JWT u OAuth2
  • Envío de archivos y registro de autoservicio para sus aplicaciones

Requisitos

  • Dolibarr 18.0 o superior, PHP 7.4 o superior
  • Extensión PHP openssl
  • Una dirección HTTPS para Dolibarr, imprescindible para OAuth2 y las aplicaciones móviles

Todas las funcionalidades se describen en la documentación en línea: doc.cap-rel.fr/smartauth

Qué incluye la compra

  • El módulo y el acceso a sus actualizaciones durante el periodo indicado en esta ficha
  • La corrección de errores, incluidos los que usted nos comunique
  • Un correo electrónico en cada nueva versión publicada

Para enterarse automáticamente de las nuevas versiones, de este módulo y del ecosistema Dolibarr en general, suscríbase en dolinews.com: allí publicamos nuestros anuncios de versión.

Soporte

El soporte pasa por nuestro formulario de soporte, no por los comentarios de esta ficha.

El soporte no es gratuito. Usted quiere personas competentes al otro lado: es normal que se les pague ese tiempo. El precio mostrado cubre el módulo y sus actualizaciones. No cubre la instalación ni la configuración de su Dolibarr, ni la formación de sus equipos, ni desarrollos específicos, ni el diagnóstico de un entorno que no alojamos nosotros.

Un error reproducible del módulo se corrige sin coste, forma parte de las actualizaciones anteriores.

Antes de comprar

  • Compruebe las versiones de Dolibarr y de PHP indicadas al principio de esta ficha: más allá, el módulo no está probado
  • Los módulos se despliegan desde Inicio > Configuración > Módulos > Desplegar un módulo externo, lo que requiere un directorio custom activo en su instalación
  • Si el módulo se apoya en un servicio en línea, la suscripción a ese servicio es independiente de la compra del módulo y se indica más arriba

Editor

Módulo desarrollado por CAP-REL, bajo licencia GPL-3.0-or-later. Documentación en línea en doc.cap-rel.fr.

Historial de versiones

2.0.54 -- 20261007

  • Stop answering any origin with credentials in CORS outside the API router
  • Require the read right and scope the dashboard, logs and push logs to the entity
  • Restrict token, device and log pages to their owner, admins and the current entity
  • Check the CSRF token on token revoke, delete and rename links and on setup links
  • Fix stored XSS in the token history and device details of the user tab
  • Revalidate the OAuth2 service user status and entity on every M2M call
  • Keep reserved payload keys out of reach of the request body
  • Apply mapper visibility rules to sync pull, push and conflict resolution
  • Never store or return secret columns in sync conflicts
  • Check Dolibarr document access rules on every listed or downloaded document
  • Revoke OAuth2 sessions on every password reset
  • Revoke mobile sessions and anonymise contact and thirdparty on account self-deletion
  • Throttle alternative e-mail requests and require a consent for the client
  • Reject redirect targets that browsers turn into protocol-relative URLs
  • Strip JavaScript from account page sections provided by other modules
  • Escape stored extrafield values in sellist label lookups
  • Lock SSO logins per address and per login with a login-wide ceiling
  • Verify user passwords against every Dolibarr hash format
  • Check typ, kid and issuer on session cookies and logout hints
  • Refuse mixed client authentication methods on the OAuth2 token endpoint
  • Serialise self-service registrations per address and refuse taken logins
  • Log out other sessions when the password is changed from the account page
  • Consume the reset token before writing the new password
  • Keep uploads and temp files under the module data root and escape download names
  • Keep a single Content-Security-Policy on the OAuth portal
  • Hide the token salt from every screen
  • Cancel the tokens and families of a deleted device
  • Refuse toggling or deleting an OAuth client of another entity
  • Escape LIKE wildcards in list searches and text filters
  • Admit internal users at the SSO login, as the Dolibarr back office SSO requires
  • Make the Dolibarr back office SSO callback reach the SmartAuth login handler
  • Show members correctly on the OAuth consent page
  • Stop the login loop when an application asks for prompt=login
  • Answer invalid_grant instead of a server error when a refresh token rotation races
  • Answer 500 instead of an empty token when token storage fails
  • Refuse to issue tokens when their device family cannot be created
  • Show the token revocation message on the OAuth logout page
  • List every OAuth client when no status filter is chosen
  • Restore the global search field of the token, log and device lists
  • Restore the application list on MySQL with ONLY_FULL_GROUP_BY
  • Fix fatal errors on category sellists, smart extrafields and links without mapper
  • Export extrafields holding 0 and keep mapper labels free of HTML entities
  • Report malformed sync changes per entry and detect delete conflicts
  • Send push notifications to recipients by entity and group rights
  • Keep the port in the VAPID audience and restrict push urgency to RFC 8030 values
  • Let admins purge the push send journal
  • Replace the route cache atomically and skip broken route files
  • Enable the cleanup job on module activation
  • Store token renames in the device label
  • Index token lookup columns and widen logged IP addresses for IPv6
  • Restore French accents and align translations without overriding core keys
  • Use Dolibarr pictos instead of emojis

2.0.52 -- 20260925

  • password reset now goes through the Dolibarr object
  • the legacy clear-text password column is cleared on reset
  • live sessions of both linked identities are revoked on reset
  • ship composer.lock
  • update phpunit to 9.6.37 (development dependency)
  • a device whose reference could not be computed
  • photo extrafield on an object with no storage path no longer builds a path
  • missing numbering addon is reported again
  • SSO login on a multi-entity instance no longer dies
  • the last-cleanup and JWT key rows are written again
  • the attached-files counter no longer counts .meta files and thumbnails
  • the sync push survives a Dolibarr method declaring a union type
  • ids and paging values read from the request are cast
  • category extrafields no longer break on Dolibarr 23
  • the dashboard no longer passes an array where llxHeader expects
  • object creation, update and deletion pass the trigger flag
  • static analysis raised from level 1 to level 6

2.0.50 -- 20260922

  • cleanup module builder stuff on admin
  • update phpstan stuff and gitlab for CI
  • move code coverage to a specific config file

2.0.46 -- 20260922

  • record whether the PWA runs installed on each logical user device
  • new manifest
  • route cache: fix the logging
  • route cache: the legacy filesystem scan
  • dmTrait resolves rowid through $id when the Dolibarr class has no $fields
  • OAuth setup forms guarded against double submit
  • memcached is flushed last in the module init
  • announced baseline aligned on Dolibarr 18.0 and PHP 7.4
  • drop the dead v16 FormSetup backport
  • module files are included through dol_include_once
  • cleanup module builder stuff
  • HTTP test suite covers every admin and list page against fatal errors

2.0.44 -- 20260917

  • photo annotations: access follows the owning module, not only the uploader
  • AnnotationsHelper::get/set delegate to the smartmaker_canAccessAnnotations hook
  • default stays deny, so modules implementing nothing keep the previous behaviour

2.0.42 -- 20260907

  • user tab: scope both lists to the displayed user
  • an admin was served every token of every user
  • user tab: entity filter on tokens and logs
  • user tab: keep the user id on ?userid= entry
  • user tab: token activity history endpoint was missing
  • user tab: fix ambiguous ORDER BY hiding both lists
  • RSA key generation no longer depends on host openssl.cnf
  • broken host openssl.cnf took the whole IdP down
  • test harness: HTTP suite for server-rendered Dolibarr pages
  • test harness: per-user temp document directory

2.0.40 -- 20260827

  • (2026 summer sprint)
  • generic REST facade objects/{objtype}
  • document line facade (add/update/delete/reorder) for order/invoice/proposal
  • document workflow actions (validate/setDraft/close/setPaid/...)
  • invoice payment facade (record/list payments)
  • CrudInvoker handles delete($rowid, $user) and classes without update()
  • supplier document lines/actions/payments
  • contract lines through the facade
  • extra update-side guards on the facade
  • sync push writes the extrafields mapper
  • fix sync push erasing the extrafields a partial payload
  • SMARTAUTH_FACADE_TYPES restricts which registry types objects/* serves on an
  • instance (CSV, empty = every type); a closed type answers like an unknown one
  • reject a JWT whose login claim now resolves to another user than its signed
  • oauth logout (RP-initiated)
  • sync register refuses (409)
  • sync conflict detection
  • sync delete: the tombstone is only created after a successful delete
  • sync raw fallback
  • sync push batches are capped (500 changes, SMARTAUTH_SYNC_PUSH_MAX_CHANGES)
  • the admin "require PKCE" toggle is now enforced
  • /refresh is rate limited per IP
  • the English password reset email body carried no %s placeholders
  • texts injected into JavaScript use transnoentities()
  • duplicate keys removed from the French lang file
  • double-submit guard (data-submit-once)
  • web push spec aligned on the shipped constant

2.0.38 -- 20260724

  • new option to disable force update password on first login
  • generic rest facade for common objects

2.0.36 -- 20260715

  • new option to get only thumbnails on request for local cache / offline
  • add entity on auth
  • cleanup warehouses code
  • trait base / dmtrait
  • add crud on base objects
  • better sync algo

2.0.34 -- 20260702

  • update add sync process regarding smartpos needs
  • add cursor for sync partial data on big database

2.0.32 -- 20260629

  • better idempotency for synced data
  • add cache for fk_keys (dolmapping)

2.0.30 -- 20260619

  • unify logs with common prefix
  • fix route and route cache for modules who commes with front react plugins
  • add more extrafields support on auto mapping system
  • add missing extrafields "list" properties (visible)
  • add "my" devices on relogin on front app

2.0.28 -- 20260617

  • better route cache support and update
  • add webpush stuff
  • better logs collect
  • policy : checkuser rights & passwords
  • update user doc
  • add more defensive code on oauth
  • better protection on spoofing tips
  • add security checks on controllers
  • user can delete / revoke own devices
  • do not hardcode custom anymore for custom dolibarr setup

2.0.22 -- 20260603

  • Add webpush subsystem for notificaitons on PWA
  • Add sso portal
  • Better log collect

2.0.21 -- 20260526

  • TokenService now scopes its JTI and access-token lookups by entity
  • RevokedJtiController caps the ?since= parameter length to 20 chars
  • Add viewport_mode column to llx_smartauth_user_devices
  • Handle viewport-mode (smartphone / tablet / desktop)

2.0.20 -- 20260521

  • Missing public folder
  • Product / Services mapping
  • Handle "" and zero values

2.0.18 -- 20260520

  • Mappers Dolibarr -> API
  • Next step for dolMapping objects
  • Include dolMapping of dictionaries
  • Handle extrafields
  • Add tests coverage
  • OAuth2 hook smartmaker_oauth_pre_token
  • TokenService::createAccessToken
  • TokenController propagates the harvested extra_claims
  • JWT revocation list
  • ResponseTrait gains sendJsonResponseWithHeaders() and sendNotModified()

2.0.16 -- 20260513

  • Add Idempotency-Key support on POST /upload (replays the 2xx response on retry instead of creating duplicate files when the PWA loses the network mid-upload). New table llx_smartauth_upload_idempotency with auto-purge in doScheduledJob (24h for completed, 10min for stale processing). Backend contract for the smartcommon useUploadQueue hook (cf documentation/SPEC_UPLOAD_IDEMPOTENCY.md).
  • Test harness: cleanSmartAuthTables() now discovers smartauth tables at runtime via sqlite_master / SHOW TABLES, no more hard-coded list to maintain.

2.0.14 -- 20260507

  • Full security review
  • Add oAuth stuff for sso

2.0.12 -- 20260428

  • Fix sanitizeRequestData : call loadExternalSchemas for external specs like photo uploads
  • Add binary upload stuff

2.0.10 -- 20260413

  • Fix all includes to use dol_include_once()
  • Add Memcached cache flush on module activation/upgrade
  • Rewrite About page: module info, feedback form, donation box, useful links, changelog display
  • Add admin CSS (css/admin.css.php) for About page layout
  • Set $help_url to https://doc.cap-rel.fr/smartauth/
  • Normalize all dol_syslog() calls with consistent "SmartAuth" prefix
  • Add missing translation keys for en_US (dashboard, user tab, OAuth, GeoIP, about page)
  • Fix missing French accents in OAuth and Dolibarr Integration translation keys

2.0.8 -- 20260303

  • add auth solution for m2m

2.0.7 -- 20260302

  • use hash share for downloads
  • add entries into ecm database if missing
  • add batch queries on documents index

2.0.5 -- 20260219

  • better tests coverage, fix bugs thanks to tests
  • fix mapping object for dolibarr like Thirdparty / Societe
  • add categories in list of objectTypeConfig
  • add catagories linked to an object

2.0.2 -- 20260218

  • dynamic manifest file - you can choose your icon and name (install app icon on desktop)
  • new offline sync system for binary files (pdf / others)

2.0.1 -- 20260210

  • oAuth2 server working with wordpress client as POC

2.0.0 -- 20260209

  • Full oAuth2 identity provider solution

1.1.2 -- 20260201

  • Add more tools for offline mode
  • Add LocalRoute system

1.1.0 -- 20260123

  • Major version
  • Auto build cache router and auto detect invalidate cache if routes changed
  • Add full CORS support
  • Fix GeoIP auto setup
  • Add PATCH support to router

1.0.16 -- 20251227

  • Fix null pointer in RateLimiter when fetch_object returns null
  • Fix undefined array keys in dmTrait and class files
  • Fix handling of non-present properties in $fields of core Dolibarr objects
  • Fix date_creation in smartlogs class
  • Fix decoded token handling in AuthController
  • Fix logs creation when user does not exist in table
  • AuthController now returns complete smartauth object with token and decoded data
  • Add status check in AuthController
  • Remove Kanban mode from list views
  • Improve test coverage with new integration tests
  • Optimize test performance with SQLite in RAM
  • Improve GitLab CI pipeline

1.0.14 -- 20251216

  • new mapping for near than all dolibarr objects
  • change naming to be as close as possible to dolibarr main api
  • new documentation
  • add an api naming convention document (rules)
  • update existing objects to apply that convention

1.0.12 -- 20251203

  • get real ip in case of proxy
  • better refresh token
  • add gps data on llx_ecm_files
  • add device_id entry
  • disable mass actions
  • use cache on get device id
  • add new route for devices
  • better next num ref for dolibarr object ref
  • fix refresh token process

1.0.10 -- 20251113

  • Auto-Install GeoIP database
  • Change ping to refresh route
  • Check refresh token
  • Optimize companies logo size
  • SmartObject type
  • SmartFileController (maybe, POC to become or not)
  • Get metadata from ECM database for files

1.0.8 -- 20251103

  • New dashboard on index
  • New user page for token list (experimental)
  • Switch to two token (access & refresh)
  • Code factoring
  • Update cron job
  • Fix for better security
  • Code cleanup
  • Use cache and new Rate Limiter
  • Better dolibarr < 18 compat'
  • Change photo and other special fields to smart* (prefix)
  • Fix options and extrafields
  • New multicompany support

1.0.5 -- 20251028

  • Fix MultiCompany errors
  • Fix extrafields without complete definition
  • Use const names (better than integer hardcoded)

1.0.4 -- 20250930

  • Add compressOptions to photo objects

1.0.2 -- 20250924

  • Firs public beta release

1.0.1 -- 20250416

  • Better payload args passed to functions
  • New dolibarrMapping classes

Para las versiones anteriores, desde la primera publicación del 04/04/2024, consulte el registro de cambios completo en la página "Acerca de" del módulo, una vez instalado.




If you think this module is a fork of another one (published after the first one) or violates some terms or conditions of use (for users or vendors), you can make a report at dolistore@dolibarr.org