8.9 KiB
title, type, sources, related, last_compiled
| title | type | sources | related | last_compiled | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Security | architecture |
|
|
2026-04-26 |
Security
Overview
Easy WMS security is built around a role-based access control (RBAC) model layered over a multi-tenant site architecture. Each user belongs to one or more roles that grant access to specific UI areas, commands, and data scopes. Security operates at three levels: authentication (who you are), authorization (what you can do), and data isolation (what data you can see).
User Roles
Easy WMS defines a role hierarchy with increasing privileges:
| Role | Scope | Capabilities |
|---|---|---|
| SuperAdmin | Organization (all sites) | Full access including user management, system parameters, all modules |
| Administrator | Organization or per-site | Most functional areas; may be scoped to one warehouse |
| Manager | Per-site | Operational supervision; can release orders, manage counts, view reports |
| Operator | Per-site | Execute daily operations: picking, receiving, counting, shipping |
| RF Operator | RF terminal only | Subset of Operator; limited to terminal flows |
| Viewer / Read-only | Per-site | Read-only access to views and reports |
| 3PL Client | Owner-scoped | Only sees data for their owner; requires 3PL Portal module |
| SCEM Admin | Cross-site | Manages Supply Chain Event subscriptions and notification routing |
Custom roles can be defined in the AD to grant fine-grained access to specific Commands, Views, and Dialogs.
Authentication
Standard login
- Web (SmartUI): Username/password authentication; session managed via encrypted cookie
- RF Terminals: Username/password entered at terminal login screen; sessions can be configured to time out after inactivity
- API (ERP Integration): API key or service account credentials; configured per integration endpoint
Password policies (minimum length, complexity, expiry) are configurable in system parameters.
QR Code login (RF terminals)
Operators can log in to RF terminals by scanning a personal QR Code instead of typing their credentials:
- The QR Code contains anonymized data — a third party who finds a lost QR Code cannot derive the operator's username or password from it
- Each reprint invalidates the previous QR Code — there is no revocation mechanism other than reprinting
- QR Code login is incompatible with SSO: a user configured for SSO cannot use QR Code login
SSO (Single Sign-On)
EasyWMS supports SSO using the SAML V2.0 protocol. No other SSO protocol is supported.
- SSO is available on both the PC (SmartUI) and RF terminal interfaces
- When SSO is enabled for a user account, EasyWMS will not accept any other login method for that user — standard username/password login is disabled
- SSO and QR Code are mutually exclusive: enabling SSO on a user account prevents them from using QR Code login
- Configuration requires setting up the SAML identity provider (IDP) in EasyWMS system parameters and mapping EasyWMS roles to IDP groups
Authorization Model
Authorization is evaluated at two levels:
Menu / UI Access
Each Role grants access to specific navigation areas. A user who cannot access a menu item cannot reach the underlying Commands or Views from the UI.
Command-Level Access
Individual AD Commands can be restricted to specific roles. This is enforced server-side — even if a user constructs an API call directly, the command execution checks the caller's role.
Data Scope (Owner Isolation)
When the Owner Extensions module is active, data is isolated by owner:
- Receipt orders, shipping orders, and master data (items, suppliers, accounts) carry an owner code
- Users assigned to a specific owner can only see and act on that owner's data
- 3PL Portal users have this isolation enforced automatically
- See Owner Extensions for details
Station Roles
Beyond system roles, operators are assigned to station roles that determine which warehouse stations they can work at. Station roles are configured per station type:
- An operator with "Receiving" role can work at Dock and PIE stations
- An operator with "Picking" role can work at PK/PS/ME stations
- An operator can hold multiple station roles simultaneously
Station role assignment is done in the Warehouse Designer or via the Stations administration view.
Audit Trail
Every significant operation in Easy WMS generates a Transaction record:
- Who performed the operation (user)
- When (timestamp)
- What (transaction type code, e.g., STK.ADJ, CON.MOVE)
- On which objects (container, location, item, order)
- From which equipment (RFT, workstation IP)
Transactions are immutable and cannot be deleted. They form the complete audit trail for stock movements, adjustments, order processing, and user actions. See Transactions for the full transaction type catalog.
Quality Locks (Stock Security)
Quality Control uses a two-tier lock system to prevent unauthorized stock movements:
- Receiving status: Set automatically during reception; cleared when stock passes QC
- User status: Set manually or via ERP STR message; cleared manually or via time-based unlock
Stock with an active lock cannot be assigned to shipping orders or moved by standard tasks. This provides a safety mechanism to prevent inadvertent shipment of quarantined stock. See Quality Control for details.
Container Locks
Containers can be locked with specific lock types that prevent certain operations:
| Lock Type | Blocked Operation |
|---|---|
| Inbound lock | Container cannot receive new stock |
| Outbound lock | Container cannot be picked or shipped |
| Movement lock | Container cannot be moved to another location |
| Blocking lock | All operations blocked |
Container lock events generate LCK.CON.001 and ULK.CON.001 transactions.
Network and Infrastructure Security
- IIS Application Pools: Run under dedicated service accounts with minimal OS privileges
- Database: Separate credentials per application pool; principle of least privilege
- API Keys: ERP integration uses API keys per connection; keys are rotated per customer policy
- HTTPS: All SmartUI and API traffic encrypted via TLS; HTTP redirects to HTTPS enforced
- RF WIFI: RF terminals communicate over WPA2/WPA3 encrypted WIFI networks
- AGV Communication: AGV systems communicate over dedicated network segments (VLAN isolation recommended)
- VPN: SaaS deployments require VPN tunnels for on-premise ERP integration and printer connectivity
Notification Security
The SCEM (Supply Chain Event Management) module allows subscribing to operational events. Subscriptions are scoped by role:
- SuperAdmin/Administrators/Managers: Can subscribe to any event type
- 3PL clients: Can only subscribe to events related to their owner
- Notification channels (email, SMS, web) are configured per subscription
Parameters Affecting Security
| Parameter | Effect |
|---|---|
SESSION_TIMEOUT_MINUTES |
RF and web session inactivity timeout |
PASSWORD_MIN_LENGTH |
Minimum password length |
MAX_LOGIN_ATTEMPTS |
Account lockout threshold |
AUDIT_LOG_RETENTION_DAYS |
How long transaction logs are kept |
Common Errors
| Symptom | Cause | Solution |
|---|---|---|
| User cannot access a menu | Role missing required permission | Add the menu item to the user's role in AD configuration |
| RF terminal login rejected | User has no station role at that station type | Assign appropriate station role |
| ERP API calls return 401 | API key expired or invalid | Regenerate API key in integration configuration |
| Stock cannot be assigned (locked) | User or receiving status active | Check Quality Control view; unlock if appropriate |
| 3PL client sees other owners' data | Owner Extensions not configured | Enable Owner Extensions module and assign owner to user |
Related
- Overview — System architecture and deployment model
- Application Dictionary — Role and permission configuration via AD
- Transactions — Audit trail for all operations
- Quality Control — Stock lock system
- Owner Extensions — Multi-owner data isolation
- 3PL Portal — External client access model
- Supply Chain Event Management — Notification subscriptions