Skip to main content

3. Scope

logo

Part of the Access Transparency manual — see also 1. Introduction, 2. What's New, 4. Setup, 5. Usage, 6. Troubleshooting.

Reference only — see 4. Setup for how to configure each of these.

3.1 Assets, management & administration items

New itemtypes

  • PluginAccesstransparencyUserinteractions — internal table storing document-open events captured by the plugin's JS tracker

Modified itemtypes

  • User — a new "Access Transparency" tab (requires the plugin_accesstransparency_view READ right to see)
  • Document — a new "Access Transparency" tab showing which users opened that document (same right required)
  • Profile — a new "Access Transparency" tab for granting/revoking the view right
  • Config — a new "Access Transparency" tab for configuring log retention and excluded logins

Permissions

  • plugin_accesstransparency_view (right name: plugin_accesstransparency_view, field: plugin_accesstransparency_view, READ) — controls access to the User and Document "Access Transparency" tabs. Assigned per-profile under Administration → Profiles → profile → "Access Transparency" tab.

Automatic Actions

  • PurgeInteractionLogs — a cron task that runs hourly by default (set via CronTask::register() in setup.php), purging rows from glpi_plugin_accesstransparency_userinteractions older than the configured retention cutoff (set under Setup → General → Access Transparency → "Log retention").

3.2 Automatic actions

The cron task PurgeInteractionLogs (class PluginAccesstransparencyUserinteractions, method PurgeInteractionLogs) runs on the schedule defined at registration time (default: hourly):

  • If retention is set to "keep all" (DELETE_ALL in PluginAccesstransparencyConfig), the task skips any deletion.
  • If retention is set to "delete all" (KEEP_ALL), every row in glpi_plugin_accesstransparency_userinteractions is deleted.
  • If retention is set to a number of months (e.g. "12 months"), rows older than current_time - (months * 30.44 * 24 * 3600) seconds are deleted.

The task is called via Session::addMessageAfterRedirect() logging the number of deleted rows.


See 4.2 Configuration.

3.3 Notifications

None.

3.4 Rules

None.

3.5 Permissions

The plugin enforces one right, checked at two points:

  1. Tab visibility — Session::haveRight('profile', READ) gates the Profile tab; Session::haveRight('plugin_accesstransparency_view', READ) gates the User and Document tabs. Both checks live in the respective class's displayTabContentForItem() method.
  2. CSV export — both export routes (front/export_user_csv.php and front/export_document_csv.php) check Session::haveRight('plugin_accesstransparency_view', READ) before serving the file.

Additionally, the CSV export routes respect standard GLPI visibility rules for the User or Document in question — a user can only export history for items they would otherwise be allowed to view.

See 4.3 Permissions.

Generated for Access Transparency 1.2.0-beta2 on GLPI 11.0.8 — 2026-08-24.