Repository navigation
EasyPDM v0.2
EasyPDM 0.2
Another big update to EasyPDM — a batch of new features, improvements to how clients and manufacturers are handled, and a number of security and bug fixes found during testing.
Highlights: notifications for events across the system, a new "Cancelled" status for items, a two-level Series/Type catalog for manufacturers, assigning projects to clients, and a thorough rework of the Clients tab — a client can now have multiple trade names (Name 2), each with its own address, contacts, and files.
On top of that: brute-force protection on login, a fix for a bug that could corrupt a shared BOM's structure, and a dozen-plus smaller bug fixes found during a security and consistency review of the app.
Full changelog below.
Added
- Notifications: a bell icon (top right, next to your name) shows a scrollable list
of events — an item you own waiting for review/released/reverted to "In progress",
a new revision on your item, being assigned to or removed from a project, an
assigned project being deleted, your password being changed by an admin, or (admins
only) low disk space on the file storage. Each type can be turned off individually
in Settings → Notifications, and each notification can be marked as read or deleted
individually (an "X" button next to each one in the bell's dropdown). - Item detail panel now shows a "Used in" section (right above History): every
assembly that contains the item, directly or through a sub-assembly, across
projects — with a button to jump straight to it. Scrollable, capped at 5
visible rows like History. - Assemblies now have a kind of their own — Manufactured, Purchased or Client's —
picked when creating one and changeable later, just like a Part's kind. Purchased
and client assemblies are numbered with the prefix of the matching Part kind; only
manufactured assemblies keep their own prefix (the existing "Assembly" one, now
labelled accordingly in Settings → Numbering). - Manufacturers can now have a two-level catalog of what they supply: Series/Types,
and Subtypes within a series, added from one row (a series picker plus a subtype
field plus Add) and listed in a filterable table below (Manufacturers tab). On a
purchased item — Part or Assembly — the "Series/Type" and "Subtype" fields sit next
to Manufacturer, always visible, side by side; each is simply disabled until the
level above it is set (Series/Type needs a manufacturer, Subtype needs a
series/type) and offers exactly the entries belonging to it, and changing a higher
level clears the lower ones. In "Whole database" the kind filter now covers Parts and
Assemblies together (choosing "Purchased" lists both), and the same
Manufacturer → Series/Type → Subtype chain appears as dependent filters next to it. - Client detail panel now lists the Projects assigned to that client (with a button
to jump straight to each one), scoped to what the current user can actually see. - A brand new, empty database now gets one sample project on first startup (an
assembly with two parts in different statuses, forming a small BOM, plus a tag) —
something to explore instead of a blank slate. A notification points it out and
reminds you to clear it (Settings → File storage → Danger zone) before real use.
Only ever created once, on a genuinely empty database. - An assembly's BOM table (and both its CSV exports) now shows a "Norm" column,
filled in from a Standard part's own Norm field. - "Whole database" gained a "Clear filters" button next to the other filters —
resets search, tag, and every filter dropdown in one click. Disabled when nothing
is currently filtered. - New item status, "Cancelled" — for a released Part/Assembly that turns out not to be
needed. Selectable only from "Released", and reversible back to "In progress" (same
revision bump + comment as coming back from "Released"). An assembly can't itself
become "Released" while anything in its BOM — at any nesting depth — is cancelled;
the attempt names the cancelled item(s) right in the status confirmation dialog.
Cancelled items are always ownerless, same as released ones, and their icon in the
tree/list turns red. - The Client-supplied kind (Part or Assembly) now has a "Client" field, picked from
the Clients catalog — previously there was no way to record which client a
client-supplied item actually belongs to. Next to it, on the same line, "Name 2" —
one of that client's second names/trade variants, offered only once a client is
picked and cleared again if you change it. A client can now have any number of
Name 2 entries instead of just one — so ten trade names for the same client no
longer means ten disconnected "Client" catalog entries to pick from. The Clients
tab's left-hand list now shows every client as a header row with its Name 2
entries indented underneath, and the "Add client" dialog is dynamic: its name
field is a picker over existing clients, and typing/selecting one that already
exists switches the dialog to adding that client a new Name 2 (confirmed with a
single "OK") instead of creating a duplicate entry. Deleting a Name 2 is a
one-click action right on its row in that list. Each Name 2 can now also have its
own address, its own contacts, and its own files (e.g. different norms for "Bosch
Rexroth" than for "Bosch Tabory"), all kept separate from the client's — its detail
panel shows the client's own contacts and files read-only (inherited by every
Name 2) above a second, fully editable section for the ones added directly under
that Name 2.
Changed
- Admins can now bypass another user's item lock for three actions: changing its
status, taking over the lock (locking it to themselves), and releasing it —
useful when a coworker is away and their in-progress item needs to move forward.
Editing properties still requires actually being the owner. - Deleting a project no longer deletes its Parts/Assemblies. It now only removes the
project itself — the items become project-less (same state as "Remove from
structure"), still fully intact with their files, attachments, tags, history, and
BOM relations, reachable through "Whole database". This also protects items shared
into another project's BOM: deleting the owning project used to silently remove
that shared item from the other project's BOM too — it no longer does.
Fixed
- Switching a Part or Assembly's kind (e.g. Purchased → Standard) didn't clear the
fields that belonged only to the old kind — a Manufacturer typed in under
"Purchased" stayed in the item's data even after switching away, invisible in the
UI but still turning up in "Whole database" search. Now cleared as part of the
kind change, both when editing an existing item and while still filling in the
"New item" dialog. - An Assembly's generic Properties editor duplicated its kind, Manufacturer,
Series/Type and Subtype as plain, freely-editable rows underneath the dedicated
fields for them further up — redundant, and easy to accidentally desync from the
real fields. - Adding a new item under a locked assembly bypassed the owner lock entirely —
anyone with project access could insert a new BOM row under someone else's locked
assembly, even though every other change to that assembly was correctly blocked. - Editing a BOM row's quantity had no error handling — a failed save (e.g. the
parent got locked by someone else) silently left the input showing the unsaved
value with no indication anything went wrong. - Deleting a Material had no confirmation dialog and no error handling — the only
one-click, unconfirmed delete left in the app. - The automatic backup schedule wrote a local-time timestamp into a column that
expects UTC. If that write failed (or silently stored the wrong time), the "did
it already run today" check could never engage, and the service would keep
retrying — creating a fresh backup every 15 minutes and pruning older, legitimate
ones well within a day. - Deleting a contact (Clients/Manufacturers) had no confirmation dialog and no error
handling — the last one-click, unconfirmed delete left in the app besides Materials
(fixed above). - A number of inline "save on blur"/"save on click" fields had no error handling —
item name, custom properties, price/currency, part kind, removing a tag, saved
filters, and per-project user access checkboxes. A failed save could look like it
went through with no indication anything was wrong. - Dragging to reorder items in the project tree, and "Remove from structure" there,
silently swallowed errors with no feedback (the equivalent actions inside a BOM
already showed errors correctly). - Deleting or demoting the last administrator had a narrow race: two near-simultaneous
requests (e.g. two admins demoting each other, or one deleting the other at the same
moment) could both pass a stale "is this the last admin" check and leave the system
with zero administrators. - Releasing an item's owner lock as part of releasing it to "Released" status wasn't
recorded in the item's History (unlike releasing it explicitly). - Quickly switching the selected project while adding a new item without a fixed
project could show parent-folder options from the previously selected project. - The Logs page could show content for the wrong date if you switched dates or hit
"Refresh" again before the previous request finished. - Re-sending a status change that didn't actually change anything (e.g. re-confirming
"Released" on an item already Released) could still fire a duplicate notification. - The status-change confirmation dialog showed two buttons, "Cancel" and "Confirm",
even when it was only displaying a blocking error (e.g. an assembly rejected from
"Released" because it contains a cancelled item) — "Confirm" did nothing in that
case. Now shows a single "OK" button instead. - Deleting an item completely could silently corrupt a shared assembly's BOM: if a
descendant of the deleted item was also used elsewhere (correctly kept), a part
reachable ONLY through that surviving descendant could still get deleted along with
it, breaking the surviving assembly's structure with no error or warning. - Adding or removing a tag never checked the item's owner lock or status — anyone
with project access could tag/untag an item locked by someone else, or one outside
"In progress", unlike every other property of the item. - The BOM CSV export didn't guard against formula/CSV injection: a manufacturer/
material/order-number value starting with=,+,-or@could execute as a
formula when the exported file was opened in Excel/Sheets. - Login had no rate limiting — the shipped default
admin/adminaccount could be
brute-forced with unlimited attempts. Now locks out after repeated failures. - The session cookie was missing the
Secureflag when served over HTTPS. - Resetting the item-number sequence (Settings → Numbering) had a narrow race: a
concurrently created item could grab a number just as the sequence was being
rewound, risking a future duplicateitem_number. Now serialized behind a
transaction and table lock. - In the "Add item" dialog, changing the selected parent could leave the create-mode
selector on a mode the new parent doesn't accept (e.g. Folder under an Assembly),
which the backend then rejected with a raw error instead of the UI preventing it. - The CAD-macro "log the browser in automatically" bridge put the macro's actual,
30-day session token directly in the URL opened in the system browser, where it
could persist in browser history. It now goes through a one-time, short-lived
exchange ticket instead — the real session token never appears in a URL.
Installation
-
Docker (recommended):
git clone https://github.com/pawelcel/EasyPDM.git cd EasyPDM ./install-easypdm-docker.sh(or
docker compose pull && docker compose up -dif you already havedocker-compose.yml— it will now always fetch this exact version, not an arbitrary newer commit). -
Windows — download
EasyPDM_Windows_v0.2.exebelow. -
Linux (without Docker) — download
EasyPDM-Linux-x64_v0.2.tar.gzbelow,sudo ./install-easypdm-linux.sh. -
CAD macros — updated in this release (browser-login security fix, see Fixed above):
EasyPDM_SW_Download_v0.2.swp/EasyPDM_SW_Upload_v0.2.swpfor SolidWorks,
EasyPDM_FreeCad_Download_v0.2.FCMacro/EasyPDM_FreeCad_Upload_v0.2.FCMacrofor FreeCAD.
Full technical changelog: CHANGELOG.md.