-
-
Notifications
You must be signed in to change notification settings - Fork 29
Cloud Applications and Renewals Developer Guide
How manually added applications coexist with agent discovery, and how licence renewals reach Watchtower and the calendar. Shipped as #1549β#1553 in 1.5.0.
The user-facing page is Cloud applications and licence renewals.
Colour key: ποΈ schema Β· βοΈ shared Β· π API Β· π₯οΈ page Β· π i18n
| π¨ | File | What it does |
|---|---|---|
| ποΈ | database/freeitsm.sql |
source, app_url, notes, created_by on software_inventory_apps
|
| ποΈ | includes/db_verify_schema.php |
The same four, for an existing install |
| π | api/external/software-inventory/submit/index.php |
The guard. The agent may adopt a manual row, never overwrite it |
| π |
api/software/save_app.php / delete_app.php
|
Manual-only CRUD, with three delete guards |
| π | api/software/get_apps.php |
Adds source and the seat subquery |
| βοΈ | includes/software_licence_calendar.php |
Renewals β calendar. Twin of asset_warranty_calendar.php
|
| βοΈ | includes/services/software.php |
Resyncs the calendar after any licence write |
| βοΈ | includes/watchtower_queries.php |
The Software card's three counts |
| βοΈ | includes/watchtower_settings.php |
Registers the card; marks it impersonal |
| π | api/software/sync_renewal_calendar.php |
On-demand rebuild when the setting is saved |
| π₯οΈ |
software/index.php, software/settings/index.php, watchtower/index.php
|
The UI |
software_licences.app_id is NOT NULL with a foreign key to software_inventory_apps.
That single line is why this feature is worth more than "type in an app name". The entire licence machinery β renewal_date, notice_period_days, quantity, cost, currency, portal_url, vendor_contact, purchase_date β already existed and was completely unreachable for anything you don't install on a machine, because there was no app row to hang it on.
The only ways in were the inventory agent, the system-info submit and Intune. A cloud platform installs nothing, so nothing could discover it, so it could not be recorded at all.
The agent's lookup is:
SELECT id, display_name, publisher, source FROM software_inventory_apps
WHERE display_name = ? AND (publisher IS NULL OR publisher = ?)A hand-typed "Adobe Creative Cloud" with no publisher therefore already matches what an agent later reports. That match is correct and deliberate β the installs should attach to the row somebody already curated rather than starting a duplicate.
What must not happen is the rest of the block running on it:
if (($appRow['source'] ?? 'agent') !== 'manual') {
// ... the "normalise to the latest values" update
}The agent reports a registry DisplayName and Publisher. A person typed a name they chose, and possibly a URL and notes beside it. Letting the agent normalise would silently replace curated text with whatever an installer wrote into the registry, with nothing on screen to say it had happened. source stays 'manual' for the same reason: the row's origin is a fact about who is responsible for its fields, not about what has since been found installed.
Posting a genuine agent payload naming a manual app returned updated_apps: 0, with the publisher, URL and notes intact and install_count going 0 β 1. Without the guard that would have been updated_apps: 1 and a rewritten publisher.
β οΈ The submit endpoint authenticates with a plainAuthorization: <key>header (noBearer), against theapikeystable β notsoftware_api_keys, which does not exist.
COUNT(DISTINCT d.host_id) as install_count,
(SELECT COALESCE(SUM(l.quantity), 0) FROM software_licences l
WHERE l.app_id = a.id AND l.status = 'Active') as seatsGROUP BY multiplies the rows against each other, and install_count would become hosts Γ licences. The same double-counting trap that a many-to-many ticket category would have been.
The two are reported side by side because they answer different questions. A cloud app is installed nowhere, and a 0 there must not be read as "nobody uses this".
Reuses the mechanism asset warranties have used for a while rather than inventing one. calendar_events.source exists precisely so a generator can wipe and reinsert its own entries without touching anything a person typed:
$conn->exec("DELETE FROM calendar_events WHERE source = 'software_renewal'");A cheap full resync β licence edits are rare, the event set is small, and regenerating the lot is the only version with no drift in it.
The renewal date is when the money goes out. The notice deadline β renewal_date minus notice_period_days β is the last day you can still walk away, and it is the one that actually costs money. A calendar showing only the renewal tells you about the deadline on the day it is already too late.
Unlike contracts, which store their own notice_date column, this one is derived. A licence with no notice period gets no notice event: there is no deadline to miss, and defaulting to 30 days would put a fictional commitment in somebody's calendar.
private static function resyncRenewalCalendar(PDO $conn): void {
try { β¦ } catch (Throwable $e) { error_log(β¦); }
}The licence is the record; its calendar entries are derived from it. A calendar table that is missing, mid-migration or momentarily locked must not turn "save this licence" into an error β the licence is already committed by the time this runs, so throwing would report a failure for something that succeeded.
The gap this closes: software_licences has carried renewal_date and notice_period_days since it shipped, and both already drove a "due soon" colour β but only for somebody who happened to open the Licences page that week. A contract expiring the same day shouted from the dashboard.
Counted with the same three windows as Contracts (30 days, 90 days, notice periods due) so the two cards can be read against each other. The notice window is expressed the other way round, because the date is derived rather than stored:
DATE_SUB(renewal_date, INTERVAL notice_period_days DAY)
BETWEEN {$todaySql} AND DATE_ADD({$todaySql}, INTERVAL 30 DAY)A licence with no notice period is excluded rather than defaulted to 30 β an invented deadline is worse than none.
Registered as impersonal in wtImpersonalCards(). A licence has no owner column at all, so scoping it to a person would hide a Β£12k renewal from everybody β the same reasoning already applied to Contracts.
An equivalent of asset_warranty_days was built and then removed. This card reports three fixed windows, so a "warn me N days ahead" number would change none of them β a setting that visibly does nothing. Assets can afford one because its card has a single window for it to mean.
The surviving software_renewal_surface key is declared as setting_keys on the Renewals tab in software/settings/manifest.php and derived by settingKeyOwners(), rather than being listed in the explicit block in includes/settings_keys.php β that block is documented as System-only.
capSelfCheck()requires everyCap::constant to be claimed by exactly one manifest tab. AddingSOFTWARE_RENEWALSwithout the tab fails it.
The claim "nothing in FreeITSM reminds anyone about renewals" was wrong, and Ed corrected it.
Watchtower already surfaced contracts expiring (expiring_30d / expiring_90d / notice_periods_30d) and asset warranties. Software was the only one of the three never wired in.
The mistake behind the wrong claim: a grep of watchtower/ returned nothing, so the conclusion was "no reminders exist anywhere". The card data is built in includes/watchtower_queries.php, not in watchtower/. A negative from one shallow grep is not evidence of absence.
- Cloud applications and licence renewals β the user-facing page
- Software Β· Watchtower Β· Scheduled Tasks
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96