GLPI 11.0 Comprehensive changelog
It’s time for a new GLPI major release, packed with many new and shiny features.
Let’s discover together the main changes.
Custom assets
Combination of genericobject and fields plugins, we integrate and rethink them to be part of GLPI directly.
An admin may create any new type of asset by defining it by a name and an icon. And so, a new menu entry will permit tech users to add assets of this type.
Capacities
An asset is composite, you may select a set of capacities, properties, or behaviors.
You may notice that one asset type can be inventoried. A GLPI (Android or full) agent may specify in its configuration the type of asset it will send to the server. You may find it useful to separate the old “Computers” menu into several types such as “Servers”, “Laptops”, etc.
Customize fields
In a “Fields” tab, you’ll be able to set up how the main form of the asset will be displayed.
You can remove, reorder, and customize every field present.
Like the fields plugin, there is now the possibility to add custom properties. A novelty compared to the former plugin, you will be able to place these at any place of the form, not only at the bottom.
Translations
Asset labels may be translated into the needed languages for multilingual companies by specifying the singular and plural forms for each.
Kooha-2024-10-07-10-08-08.webm
Custom Dropdowns
Similar to custom assets, new types of dropdowns can be created in Setup > Dropdowns. These dropdown types can be used in custom assets with the Dropdown custom field type.
Migration
The latest official version of the GenericObject plugin for GLPI 10 is 2.14.14.
If you plan to migrate your GLPI instance to version 11 and have not installed the latest 2.14.14 version on your GLPI 10.0.x instance, a specific transitional version compatible with GLPI 11 is available.
⚠️ Warning: The latest final version is an EOL (End of Life) release. It no longer receives functional updates or security fixes.
Purpose of this transitional version
This version serves as a migration facilitator and acts as a transitional plugin. Its main objectives are:
Update database tables and data to prepare their final state for GLPI 11.
Ensure the necessary compatibility for the automatic migration of objects and forms to the GLPI 11 core.
Usage instructions
After migrating to GLPI 11, install the latest final version.
Run the data migration operation using the following command:
php bin/console migration:genericobject_plugin_to_core⚠️ Warning: If you have added additional fields to your GenericObject items using the Fields plugin, you should update the plugin to the latest GLPI 11–compatible version. This version includes a dedicated migration method to properly associate these fields with GLPI’s CustomAsset system, which previously relied on
GenericObject.Uninstall the genericobject plugin after the migration, once all data has been fully integrated and verified within the GLPI 11 core.
Forms
We worked on the native integration of the formcreator plugin. We developed the feature from the ground up by prioritizing the user experience.
We should have covered most of the features of the former plugin, and the provided migration should find your existing forms.
The interface tries to be as close as possible to the rendering that will be presented to the user by hiding most of the advanced configurations; A preview is still available to check without admin controls. You can select an existing question to show more controls (set a default value or make a field mandatory). Every general action, like adding new parts, reordering, or editing them, can be done directly on the unique editor page.
You have access to several types of questions, and they are grouped by common behavior (for example, a short answer can be a text, an email, or a number).
Questions can be placed in a horizontally split layout. It can contain up to 4 questions.
Visibility of one question can be set in function of other questions.
Access restriction
The tab for controlling who can fill out the form shows quickly and easily who can use it.
Destinations
The “Items to create” tab permits the setup of one or several assistance objects that will be created with the answers of a user. By default, a ticket will always be created.
In detail, you can define each field of the object (a ticket for the below example).
The interface will suggest which tags you can use.
Also, we try to match the interface of the target objects to ease the setup. Fields should be found in the place you are used to.
Translations
Forms could be entirely translated into all languages already available in GLPI.
We provide a summary interface where you can find the advancement of the translation of your form.
Here is the translation editor that opens when you select a language and where you will save your sentences.
Misc
Allow helpdesk form fields to be preset using GET parameters (#19043)
Migration
The latest official version of the Formcreator plugin for GLPI 10 is 2.13.10.
If you plan to migrate your GLPI instance to version 11 and have not installed the latest 2.13.10 version on your GLPI 10.0.x instance, a specific transitional version compatible with GLPI 11 is available.
⚠️ Warning: The final version is an EOL (End of Life) release. It no longer receives functional updates or security fixes.
Purpose of this transitional version
This version serves as a migration facilitator and acts as a transitional plugin. Its main objectives are:
Update database tables and data to prepare their final state for GLPI 11.
Ensure the necessary compatibility for the automatic migration of objects and forms to the GLPI 11 core.
Usage instructions
After migrating to GLPI 11, install the latest final version.
Run the data migration operation using the following command:
php bin/console migration:formcreator_plugin_to_coreUninstall the formcreator plugin after the migration, once all data has been fully integrated and verified within the GLPI 11 core.
New self-service portal
To accompany the new forms, a fresh “self-service” portal for users has been developed.
The tiles provided are customizable. We provide a default set, but each of them is replaceable or modifiable.
You can customize this page by adding more tiles, changing their texts, and reordering them. This can be done in Profile and Entity management.
Users will also have access (by a unique tile) to a new service catalog. It will display all your active forms with:
their title and description
An icon or an illustration
Each tile can be set up within the form page. You can customize the texts and the related icons.
Open source illustration library
The work on forms and the self-service portal required a lot of custom illustrations from our design team.
All of these designs have been grouped into a new repository: glpi-project/illustrations
We released the library with a complete open-source license.
Two-factor authentication (#13926)
GLPI 11.0 introduces a significant enhancement to the platform's security features with the addition of Enhanced Two-Factor Authentication (2FA).
This additional layer of security adds an extra layer of protection to user accounts, making it more difficult for unauthorized users to gain access.
We use Time-based One-Time Passwords (TOTP) algorithm for generating tokens. It’s the most used standard, and you can create codes with well-known applications such as Google Authenticator, Authy, 2FAS, etc.
Accounts required to be secured by 2FA can be set up globally, per profiles, groups, or directly user by user.
A grace period may be configured to give users some time to configure 2FA before it becomes mandatory as well.
Webhooks (#14916)
Webhooks allow GLPI to send HTTP requests to external applications or services in response to specific events or actions within the platform. This feature enables users to integrate GLPI with other tools and services, such as chatbots, project management tools, and ticketing systems, to automate tasks and improve efficiency.
You will be able to
control methods and headers,
customize sent payload (a default one is provided),
preview what would be sent with an existing object of GLPI,
Filter the effective send by using a set of criteria,
check the queries log with their detail and test again a send.
New high-level API with swagger (#12221)
The new API is designed to make it easier for developers to integrate GLPI with other tools and services.
We moved (again) to a more high-level design with crafted endpoints mapping to low-level objects of GLPI.
This will ease the maintenance, and avoid most deprecation management we had with the former API.
Speaking about that, the legacy will be kept but discouraged for new usage. The old URLs remain and we will try to keep the consistency of answers.
With the help of Swagger and OpenAPI, we also provide a new dedicated UI and standard documentation.
The new API also includes a GraphQL interface.
OAuth server (#13304)
With the previous topic, HL API, we needed a way to have better security when sending queries to GLPI.
So we integrated an OAuth server in GLPI.
You can now declare “clients” who will consume APIs.
Grant types are available for several scenarios of exchange between GLPI and external services, a few examples:
“Client credentials” for M2M
“Authorization code” is for identity providers or general API usage.
Also, scopes allow limiting what a client has access to (API, Inventory, email, etc)
A specific additional case, since the 1.10 version, GLPI Agent supports OAuth authentication (with “client credential” grant type).
GLPI 11.0 adds a way to require agents to send this authentication before storing any inventory information in the database. Note: We also support basic access authentication (#17834), mainly for compatibility.
Filter notifications (#14403)
The notifications can now be filtered before being actually sent (by email, the browser, etc).
We use the GLPI search engine to check the current item matches a set of saved criteria.
Assistance improvements
Business Rules for Changes (#11025) and Problems (#14766)
Changes and Problems now have their dedicated rules set.
They share the same criteria and actions of Tickets rules except those related to SLA and mail collector.
This will help automation of these objects by triggering updates on related object.
Validation improvements
They now support templates (#14738)
In tickets and changes, validation tab now supports multiple steps
You can set different thresholds for each steps.
To help also with the filtering of the tickets in Technician’s views, we added a new status for ticket “Approval”.Add Satisfaction Surveys for Changes (#11076)
Allow limiting available statuses in ITIL Templates (#11138)
Group approval requests (#11006)
Add missing links between ITIL Object (#10989)
Add “View new tickets” right (#14747)
Ticket external ID field (#15105)
Create a new user from a ticket (#11224)
Approval reminders (#11623)
Users are added as observer when they are mentioned on GLPI ITIL Items
Users are added as assigned to when they are added to a task (#16033)
Assets improvements
Processes (#11978) and environment variables (#12625) lists
If an asset is automatically inventoried by a GLPI agent, the latter can send data about running processes and declared environment variables since a long time (there were available in the raw JSON).
We now display dedicated tabs to presents this information if it is present.Multiple groups for assets (#16760)
Group fields for any asset will now support multiple values
New rights have been added to allow a more granular vision of assets associated with groups.
If users are part of a group, you can forbid them to view or update all assets, and specify by their groups which ones they have access to.
display icons in the devices list for an item (#16081)
Each line of component is prefixed by an icon representing its type.
Graphical network panels (#15229)
You can now define, in models that can be inserted in a rack(Network equipment, Enclosures, etc), graphical zones on their background images where a network port is present. A label and a number can be added to the zone representing the port.
In the “Network ports” tab of any asset using the model, the background images will be displayed at the top, and ports will be highlighted, annotated with the label and the status (green/red pills)
Comprehensive schema for Inventory related rules (#18969)
Add rule system to define
itemtypebefore inventory (#19020)
UX / UI QOL
Compact search UX (#15861)
We reviewed how the list and the search criteria are displayed:
criteria and orders is indicated within a colored badge on top on the list,
criteria form is now in a dropdown panel,
a summary of criteria is displayed when the dropdown is folded,
if a “saved search” (bookmark) has been loaded, its name will be recalled instead of the summary,
the list of “saved searches” has been moved to the left of the criteria dropdown,
secondary actions have been reorganized and ordered by their importance
the position of the pagination controls can now be on top or bottom of the list, by user’s preference (#14748)
Display preferences UX improvements (#15301)
The modal to edit the displayed columns in a list has been refreshed.
You can also now drag and drop lines in this view.
From “Setup > General > Search result display”, you now can reset to default columns for all users. This could be useful when someone added too many columns to general view and broke the results page.
Note also, that you can now setup display preferences for the self-service portal (#18001)
Timeline private state clearer (#16190).
The sub elements of the timeline in assistance object display their private status with a clearer effect.
When you toggle the private flag, a dashed border appears around the form window.
This border style is also applied to existing items in timeline.
Review Notes UI (#16094)
A quick refresh of the notes interface with Twig and Tabler.
Dashboard palettes (#12884)
You can now change the default palette used by a card in dashboard system. A list of predefined set of colors is provided. Plugin developers can also provide their own.
Icons in object tabs (#13449)
Most tabs of any object of GLPI will now have an icon representing its purpose.
LDAP tests improved (#14205)
LDAP servers now have a “Test” tab making a bunch of comprehensive tests and displaying the results to help you understand issues (connection, passwords, bind, etc)
Review DB replica tab (#15594)
In the same idea, replicas make tests and report issues (error, offsets, etc) to you.
Logs viewer (#12636)
There is now a viewer for log files present on filesystem.
This feature will help, in cloud context and closed hosting environment, to grab details about errors happening in GLPI.
Code modernization
Removal of auto-escaping (#14302)
Move the root of GLPI to
/public(now mandatory) (#13197)Massive migration to Twig for views
Drop MyISAM support (#18017)
Minimum requirements are now PHP 8.2, MySQL 8.0, MariaDB 10.5 (#16893, #15841, #12235)
Pentest
As seen above, GLPI 11.0 moved from auto-escaping of HTTP requests to prepared SQL queries.
This change should step up the security of the application regarding SQL injections. It’s a long-due change but it’s ready now.
To validate the changes, we made with the help of Yogosha, a pentest session from 23rd to 30th September.
People affected by the program found vulnerabilities in GLPI main branch, mainly XSS, and a few were valid on 10.0/bugfixes branch (a security release including fixes has been done since). Still, nothing was reported on the focus of SQL injection (and RCE).
Before the final release of GLPI, a bounty program will probably be done to ensure a good quality release regarding security.
Misc
Regular inspections (#11304) (by Patrick Delcroix)
Source code integrity (#15345)
Detection of overwritten installation (#12911)
New timeline week view in planning (#13413)
Dev containers available on the root of the GitHub project (#14942)
Demo state for dashboards (#16305)
Add CLI commands for managing users (#17378)
Password history (#13911)
Add GLPI_ENVIRONMENT_TYPE constant (#15183)
Clone profiles (#12387)
Entities note in tickets (#11356)
Use Search Engine for Logs (#11229)
Delegate validations (#12504)
Use the search engine to display consumables (#15280)
Add screen capture feature (#16353)
Add more control over Marketplace availability (#11650)
Add recipient exclusions for notifications (#16355)
Knowledge base notifications (#15471)
Add user option to explicitly refuse all notifications (#14679)