You are viewing limited content. For full access, please sign in.

Question

Question

ImportAgent and/or QuickFields Connecting to Repository Via WebClient

asked on June 13, 2024

We have a Laserfiche environment where Laserfiche is on one server and LFDS & WebClient are on the Web server.  The Web server is externally exposed so people can log in while not on the network.  They have a location that is not on their network, that wants to be able to do bulk uploads into Laserfiche via either ImportAgent and/or QuickFields.  While QuickFields does allow authentication via LFDS, it does not appear to allow importing via the WebClient service.  And ImportAgent appears to be less capable as it does not even allow for LFDS authentication.

  1. Does anyone know if there is a way to have ImportAgent and/or QuickFields import documents into Laserfiche via web services, without being able to directly access the Laserfiche service?
  2. Is Laserfiche planning to allow for this down the road or are they only allowing for this type of setup with their Cloud offering?
0 0

Answer

SELECTED ANSWER
replied on June 13, 2024

No. Import Agent and Quick Fields need to be able to access the Laserfiche Server.

 

1 0
replied on June 13, 2024

Anything on the long-term roadmap for this to be setup, similar to how both can use Laserfiche Cloud's web services?

0 0
replied on June 14, 2024

Import Agent is not something I would ever expect to be running externally because it is more for "pulling" things into Laserfiche and there are many ways to bring the files in while still hosting it on the inside.

When we need to allow documents to be imported from external sources, we create a path that is accessible via VPN, trust relationships, FTP, etc. and monitor those folders with Import Agent running within our network.

Basically, we only ever run Import Agent on the receiving end, and when we need to pull things in from the outside, we set up a "drop zone" rather than putting the entire import agent on the outside.

2 0
replied on June 17, 2024

Jason, while I agree with you , we have tried these options but the customer will not accept any.  As Laserfiche has set up ImportAgent to be installed locally and work with their Cloud setup, I was hoping they would do something similar for their on-prem customers.  Their scan client for the WebClient allows someone to scan a document locally and then pass it into Laserfiche via the WebClient, why not allow ImportAgent at least the option to do the same?

0 0
replied on June 17, 2024

 

It is not a trivial technical task. The Scanning -> Web Client mechanism is a user-interactive one that relies on browser sessions and the WebTools Agent utility to act as an authentication cache. Import Agent currently doesn't even have the concept of a browser (which it would have to run headless), and has no integration points with WebTools Agent. 

Laserfiche Snapshot, which is at least user interactive and has a common enough legitimate use case for wanting to go through Web Client, still doesn't support that due to technical challenges.

Import Agent with Laserfiche Cloud does not relay through Web Client. It directly connects to a Cloud endpoint that's the logical equivalent of a self-hosted Laserfiche Server. Outside of added compatibility with Cloud's ACS authentication system, it fundamentally works the same way as on-prem.

This is the first time I've heard of anyone wanting to do that with Import Agent, and the use case, to be generous, is niche. Speaking plainly, it would not pass a feature request review, especially given the implementation effort and wide availability of viable workarounds to address the use case.

@████████'s approach here is correct. Host Import Agent on the same internal network as Laserfiche Server. Figure out a way to copy/move content from the external file location to the internal one. There are tons of options for this. Or propose something like Azure Files where both sides can have authenticated access to a hosted file share.

1 0
replied on June 18, 2024

Thanks for all of the suggestions.  I figured it was a tough ask but had to give it a try based on the unique requirements by this customer.  We've had the discussions for all of these possible workarounds (plus a hundred others) but no luck in getting them approved.  At this point we are looking at the Laserfiche API to bring in the documents.  I really do appreciate all of the ideas!

1 0
replied on May 27

I just wanted to bump this request.  We have quite a few customers who have their Laserfiche environments hosted in AWS/Azure but that do not have a site-to-site VPN configured. They are wanting to automate the import of documents to this hosted environment from various on-premise 3rd party options (e.g. HRIS, ERP, shared MFD, ...). Currently we are having to use SFTP to transfer those files to the hosted environment and then use ImportAgent/QuickFields to process them.  It would help a ton having ImportAgent/QuickFields locally installed in their environment and then it could pass the processed documents into Laserfiche via the WebClient.

0 0
replied on June 8 • Show version history

Hi Beau,

Unfortunately, won't be on the list for the same reasons I outlined above. Import Agent and Quick Fields don't have the basic, foundational integration points for browser-based interactive flows, and are written with the RepositoryAccess/LFSO .NET libraries which target Laserfiche Repository Server directly. What you're asking for isn't simply "point Import Agent at Web Client", it's "Write an almost entirely new application with the same core functionality as Import Agent that speaks Web Client instead of Repository Server".

We're not going to do that when such well-established and secure methods for moving the files already exist. I don't love SFTP any more than the next person, but a whole lot of industry standard wheels have already been invented here.

This smells like an XY Problem though. 

You might consider running a public-facing instance of Laserfiche API Server with inbound network access restricted to only the known on-prem egress IP address and then write a small program (using least-priv credentials that restrict it exclusively to importing to specific folders you need and NOTHING ELSE) that runs at the on-prem sites to upload docs through the API Server. Once in the repo, you can further process them with Workflow and/or Quick Fields. 

Ideally this is behind a reverse proxy with a web application firewall (WAF), in addition to the firewall restrictions. Do NOT expose API Server to the general open internet by itself. It doesn't have its own built-in safeguards against brute force auth attempts, etc., which are expected to be handled at a layer above it.

1 0
replied on June 11

Makes sense.  Thanks for the details, along with the other options.  We are still pushing for the customers to have a site-to-site VPN just for this traffic but I like the API method and will dig into it.  

1 0

Replies

You are not allowed to reply in this post.
You are not allowed to follow up in this post.

Sign in to reply to this post.