Files
mcp-wms-wiki/wiki/architecture/security.md
T
arthur 9ce6ae37be lint(standard): corrections completes mode standard
- Em dashes: 1712 remplaces par tirets simples (86 fichiers + _index.md,
  en-tete section Limagrain conserve)
- Checklists: 24 '- [ ]' -> '- ☐' (3 pages operations, plus de todos Obsidian)
- Ancres: 33 reparees (slugs GitHub + ancres HTML <a id> reconnues),
  1 reciblee (manuel de reten)
- related: tenseflow -> tense-flow, pie -> mechanical-elements,
  group.md retire (doublon shipping)
- Registre: compteur global 122 -> 131 pages
- Rapport racine _lint_report.md mis a jour (scan v2 + re-scan final: 0 anomalie)
- Aucun fichier limagrain/ modifie (cloisonnement)
2026-07-20 13:01:21 +02:00

8.8 KiB

title, type, sources, related, last_compiled
title type sources related last_compiled
Security architecture
areas/security/index.md (404 - compiled from cross-source knowledge)
areas/parameters.md
areas/inventory_management/stations/roles.md
modules cross-source knowledge
custom/analyse_fonctionnelle.md
architecture/overview.md
architecture/application-dictionary.md
modules/billing-3pl.md
modules/3pl-portal.md
modules/owner-extensions.md
2026-04-26

Security

Overview

Easy WMS security is built around a role-based access control (RBAC) model layered over a multi-tenant site architecture. Each user belongs to one or more roles that grant access to specific UI areas, commands, and data scopes. Security operates at three levels: authentication (who you are), authorization (what you can do), and data isolation (what data you can see).

User Roles

Easy WMS defines a role hierarchy with increasing privileges:

Role Scope Capabilities
SuperAdmin Organization (all sites) Full access including user management, system parameters, all modules
Administrator Organization or per-site Most functional areas; may be scoped to one warehouse
Manager Per-site Operational supervision; can release orders, manage counts, view reports
Operator Per-site Execute daily operations: picking, receiving, counting, shipping
RF Operator RF terminal only Subset of Operator; limited to terminal flows
Viewer / Read-only Per-site Read-only access to views and reports
3PL Client Owner-scoped Only sees data for their owner; requires 3PL Portal module
SCEM Admin Cross-site Manages Supply Chain Event subscriptions and notification routing

Custom roles can be defined in the AD to grant fine-grained access to specific Commands, Views, and Dialogs.

Authentication

Standard login

  • Web (SmartUI): Username/password authentication; session managed via encrypted cookie
  • RF Terminals: Username/password entered at terminal login screen; sessions can be configured to time out after inactivity
  • API (ERP Integration): API key or service account credentials; configured per integration endpoint

Password policies (minimum length, complexity, expiry) are configurable in system parameters.

QR Code login (RF terminals)

Operators can log in to RF terminals by scanning a personal QR Code instead of typing their credentials:

  • The QR Code contains anonymized data - a third party who finds a lost QR Code cannot derive the operator's username or password from it
  • Each reprint invalidates the previous QR Code - there is no revocation mechanism other than reprinting
  • QR Code login is incompatible with SSO: a user configured for SSO cannot use QR Code login

SSO (Single Sign-On)

EasyWMS supports SSO using the SAML V2.0 protocol. No other SSO protocol is supported.

  • SSO is available on both the PC (SmartUI) and RF terminal interfaces
  • When SSO is enabled for a user account, EasyWMS will not accept any other login method for that user - standard username/password login is disabled
  • SSO and QR Code are mutually exclusive: enabling SSO on a user account prevents them from using QR Code login
  • Configuration requires setting up the SAML identity provider (IDP) in EasyWMS system parameters and mapping EasyWMS roles to IDP groups

Authorization Model

Authorization is evaluated at two levels:

Menu / UI Access

Each Role grants access to specific navigation areas. A user who cannot access a menu item cannot reach the underlying Commands or Views from the UI.

Command-Level Access

Individual AD Commands can be restricted to specific roles. This is enforced server-side - even if a user constructs an API call directly, the command execution checks the caller's role.

Data Scope (Owner Isolation)

When the Owner Extensions module is active, data is isolated by owner:

  • Receipt orders, shipping orders, and master data (items, suppliers, accounts) carry an owner code
  • Users assigned to a specific owner can only see and act on that owner's data
  • 3PL Portal users have this isolation enforced automatically
  • See Owner Extensions for details

Station Roles

Beyond system roles, operators are assigned to station roles that determine which warehouse stations they can work at. Station roles are configured per station type:

  • An operator with "Receiving" role can work at Dock and PIE stations
  • An operator with "Picking" role can work at PK/PS/ME stations
  • An operator can hold multiple station roles simultaneously

Station role assignment is done in the Warehouse Designer or via the Stations administration view.

Audit Trail

Every significant operation in Easy WMS generates a Transaction record:

  • Who performed the operation (user)
  • When (timestamp)
  • What (transaction type code, e.g., STK.ADJ, CON.MOVE)
  • On which objects (container, location, item, order)
  • From which equipment (RFT, workstation IP)

Transactions are immutable and cannot be deleted. They form the complete audit trail for stock movements, adjustments, order processing, and user actions. See Transactions for the full transaction type catalog.

Quality Locks (Stock Security)

Quality Control uses a two-tier lock system to prevent unauthorized stock movements:

  • Receiving status: Set automatically during reception; cleared when stock passes QC
  • User status: Set manually or via ERP STR message; cleared manually or via time-based unlock

Stock with an active lock cannot be assigned to shipping orders or moved by standard tasks. This provides a safety mechanism to prevent inadvertent shipment of quarantined stock. See Quality Control for details.

Container Locks

Containers can be locked with specific lock types that prevent certain operations:

Lock Type Blocked Operation
Inbound lock Container cannot receive new stock
Outbound lock Container cannot be picked or shipped
Movement lock Container cannot be moved to another location
Blocking lock All operations blocked

Container lock events generate LCK.CON.001 and ULK.CON.001 transactions.

Network and Infrastructure Security

  • IIS Application Pools: Run under dedicated service accounts with minimal OS privileges
  • Database: Separate credentials per application pool; principle of least privilege
  • API Keys: ERP integration uses API keys per connection; keys are rotated per customer policy
  • HTTPS: All SmartUI and API traffic encrypted via TLS; HTTP redirects to HTTPS enforced
  • RF WIFI: RF terminals communicate over WPA2/WPA3 encrypted WIFI networks
  • AGV Communication: AGV systems communicate over dedicated network segments (VLAN isolation recommended)
  • VPN: SaaS deployments require VPN tunnels for on-premise ERP integration and printer connectivity

Notification Security

The SCEM (Supply Chain Event Management) module allows subscribing to operational events. Subscriptions are scoped by role:

  • SuperAdmin/Administrators/Managers: Can subscribe to any event type
  • 3PL clients: Can only subscribe to events related to their owner
  • Notification channels (email, SMS, web) are configured per subscription

Parameters Affecting Security

Parameter Effect
SESSION_TIMEOUT_MINUTES RF and web session inactivity timeout
PASSWORD_MIN_LENGTH Minimum password length
MAX_LOGIN_ATTEMPTS Account lockout threshold
AUDIT_LOG_RETENTION_DAYS How long transaction logs are kept

Common Errors

Symptom Cause Solution
User cannot access a menu Role missing required permission Add the menu item to the user's role in AD configuration
RF terminal login rejected User has no station role at that station type Assign appropriate station role
ERP API calls return 401 API key expired or invalid Regenerate API key in integration configuration
Stock cannot be assigned (locked) User or receiving status active Check Quality Control view; unlock if appropriate
3PL client sees other owners' data Owner Extensions not configured Enable Owner Extensions module and assign owner to user