Solved Webclient BLFs

Status
Not open for further replies.

Jérôme Wentzel

Premier Customer
Joined
Aug 14, 2019
Messages
31
Reaction score
6
Hello,

Can we block the BLF settings pan in the Webclient / 3CX Apps ?

The idea is to make sure people cannot configuring it themselves.
If call pickup can be blocked, an HW phone can anyway see who is calling who when a BLF is configured even if the user is not part of the same group.
That is exactly what I want to avoid.

Best regards
 
  • Like
Reactions: K.A.R.
Hello,

No this cannot be blocked. It is designed so it can give the user the chance to manage their own extension.

If you don't want the users deskphones to be able to affect them, simply inform them that if they change their extension settings it will also affect the deskphone. So if they changed something, they can change it back.

If you don't want people to see who is calling who, then this is managed by the Group rights
 
Hello JohnS !

Thanks for the feedback and the time taken to answer.

I see is a big privacy/security problem in certain cases.
I try to explain why in a understandable way.

Context:
People all have a deskphones and no softphone or Webclient.
People of a group needs to see who is calling who. BLF and groups is the solution here.
On the phones, that works fine, you can see the presence of people and if they are in a phone call or not.
That is great.

PBX we replaced had the functionality called "call supervision". That means that for certain group of people, call made to certain extensions is displayed on the fix phone.
We could re-implement the same basic functionality on Yealink phones using the option features.pickup.blf_visual_enable =1
So such provisioned phones will display callers of configured BLFs.

Problem:
Even if an extension that is configured as BLF on the phone is not in the same group, the phone will display the call.
For instance John is the Senior COO. Alex is an employee from billing.
John and Alex are not in the same group.
Alex decides to configure a BLF via the webclient with John's extension.
The result is that Alex will see incoming all calls for John.

Possible solution:
1. Remove the option in the phone -> that will break the needed call supervision functionality on desk phone. That is not an option for our customer, so we will need to find another PBX solution.
2. Remove all the deskphone -> that is also not an option
3. Hide the BLF configuration from the webclient -> I understand that this would be a feature request
3. Do not provide the webclient to our customers -> That is really sad :(
4. Any other idea would be much appreciated.

Many thanks for your time and your help.
I am sure that we are not the only ones potentially affected by this.
 
Just for clarity: BLF does not equal Presence


BLF = Buttons on deskphones that monitor call state (Idle/Ringing) and is unrelated to presence. You can pickup the CEO's incoming call using BLF but there is an option to block this from the PBX General setting page.
1594295865315.png

Presence = Visible only in 3CX clients and monitors status, call state, and provides more rich information. Group Rights can prevent others from seeing who is calling you if you untick "show calls".
1594295826475.png

It's also possible to allow managers to monitor calls, and regular users to not be allowed.
 
I agree with the clarification :)

Concerning the BLF.
Pickup is right set in the general options.

I have John the senior COO in the group COO as user.
Alex is in the group billing as user and has one BLF configured for John.
None of them are in the group Default or other group.

Group COO and Billing user right assignment looks like this:
1594309901121.png

If anybody calls John, Alex will see the following on her phone.
1. John <- Caller extension or DID
1594309967666.png
Alex won't be able to pickup the call from her phone.
Alex won't be able to see the call on the web client.
Alex only sees calls made to John on her desk phone as the picture attached.

To me that means that BLF can be used to watch who is calling who without being able to see who is doing it / prevent this to happen.

I hope that it is more clear :)

Group
 
Hi Jérôme,

Thanks I understand perfectly now. You see I was confused at first because by default our templates do not enable such a feature on the phone and you either need to modify it from the WebUI which requires you know the password, or you need to have modified templates, thus exposing the number on the screen.

How were your phones provisioned?
 
Easy ! Screenshots are always helpful :)

We enable that on the phones, I found the solution on the forum and that was confirmed by the Yealink documentation as well. That is the only way as far as I could understand (web + our vendor) to make sure we can deliver the same functionalities than the traditional PBX we are replacing with 3CX.
We speak about around 600 SIP phones to migrate to Yealink/3CX.

Of course we (IT) are the only one able to login on phones to enable it.
This is how we planned to secure the use of the SIP subscribe / notify function as explained really well here https://www.3cx.com/blog/voip-howto/busy-lamp-field/. Of course we also licensed 3CX, I understood here that it may be a licensing problem (https://www.3cx.com/community/threads/solved-blf-subscribe-rejected.48401/)

So basically that would not be a problem if people could only select the extensions being in the same groups from the webclient BLF configuration.
This sounds to be the easiest way to me; at least less complicated that to reject SIP subscribe requests based on requestor's groups.

Does that make sense to you too ?

Best regards
 
Since this is a special case for your deployment, yes it does make sense to me.

However, the problem arises because you enabled a feature that we keep disabled by default so I don't think there is enough justification for 3CX to change the way the Webclient works.

Unfortunately you will have to either disable this and go back to our default setup, or deal with the problem some other way:

1. Don't give people webclient access - this is not ideal in my opinion
2. Use our default templates and lose the the ability to see who is calling the BLF monitored extension

3. The best solution: Use deskphones together with the webclient. The users that are authorized to see calls, can see numbers from there. The users that are not authorized will not see it from the webclient nor will they see it from the BLFs (if you don't modify our default provisioning)
 
Nice way to say that this is not supported :)

As you can imagine that is really problematic for us of course. I cannot ask our users to have phones + web page opened. Main reason is that web page will not "popup" in case of call is made to a BLF and they cannot have it opened during the entire day.

So for us the only solution would be to disallow the web client to all and ask for a feature request to hide extensions in the webclients BLF configuration if I understand right :(
That is sad because you have done a great job here.

Do you think that this feature request will be feasible and make sense to you guys ?
That would be a great function without a big change in the code. I am sure many customers may come from PBX where that is possible, that would help your partners to win projects and extend your market share.

Best regards
 
Hi Jérôme

I think what you are asking in effect is more granular control over what features can be hidden/shown within the Webclient so you can customize it to your needs.

This is not currently on the V16 roadmap, but this can change in the future as we plan to further develop the webclient to encompass everything 3CX. You can look at our ideas section if there are any similar ideas and upvote them for consideration https://www.3cx.com/community/forums/web-client.71/

Please note that you cannot post it as a new Idea, this is something Gold Partners and above can do so you can contact your partner if you have one and suggest it, and they can post it at their own discretion.
 
Hello!

Ok, I will then address that via our partner and vote as you mentioned.

Until then, would it be possible to screen BLFs that are configured in 3CX for the extensions via an API ?

If so, I would write few lines of code and share it here to detect when a BLF has been configured with certain extensions and report it to the IT.

That could be an interesting compromise and helpful for others.

Best regards
 
In order to prevent users to configure BLF from yealink desk phone the following options must be configured:

linekey.type_range.custom = 0,12,13
programablekey.type_range.custom = 0,12,13
expkey.type_range.custom = 0,12,13

It works with firmware version 96.85.0.5

The following values are possible (extract from the Yealink administrator guide 58.1)
1595254981861.png

Next step is to see how to detect people who configured BLFs from sensitive people via the web client.
@JohnS_3CX do you have any direction for me concerning that topic ?

Best regards
 
I can't find the information about BLF configuration in the DB "database_single"

Are the information saved somewhere else ?

These are the tables I could checked.

Name
--------------------------
announcement
audiofeed
audiofeedcontent
blacklist
calendar
calendarhours
callcent_ag_dropped_calls
callcent_ag_queuestatus
callcent_queuecalls
calldetails
callhistory3
chat_conversation
chat_conversation_member
chat_dest2chat_mess
chat_history_mess
chat_message
chat_participant
chat_results
cl_calls
cl_participants
cl_party_info
cl_segments
codec
codec2gateway
conferenceplaceextension
conferenceplaceproperties
devinfo
dn
dngrp
dnprop
dnrange2rule
eventlog
eventmessage
extblf
extdevice
extension
extensionforward
extensionrule2profile
externalline
faxextension
fwdprofile
gateway
gatewaytplvalue
grp
grpprop
gwpar
gwpar2gateway
gwpar2parvalue
gwparvalue
holiday
inboundrule
ivr
ivrmenuitem
meetingsession
myphone_callhistory_v14
outboundroute
outboundrule
parameter
parkextension
phonebook
phonedevice
prompt
promptlang
provider
prstorage
queue
queue2dn
queue2managerdn
recording_participant
recordings
ringgroup
ringgroup2dn
routepoint
rule2grp
rule2line
rulecalltype
rulecondition
rulehours
s_push
s_qcallback
s_reporterconfig
s_reportrequest
s_sbc
s_scheduledconf
s_wakeupcalls
s_wmqueue
specialmenu
tenant
tenantprop
users
voicemail
 
This will not work as you will probably never give any info about the DB ;)

The idea would be to test certain numbers configured as BLF and avoid that it gets configured on the phone directly from the template.

What are the operators I could use other than {IF} {ELSE} {ENDIF} ?
Can I test variables ? Something like

{IF %%PickupValue%% = extensionnumber1,extensionnumber2,extensionnumber4}

Is it possible to use something else than IF and ELSE in the templates ?

Best regards
 
Hi Jérôme

The templates are not a scripting language, ultimately it provides a static file to the phone to provision various values, it does not run any operators on the phone

As for detecting the BLFs externally I'm afraid I cannot provide any assistance there either, but I can tell you that our backups will contain this information (found in the root folder of the backup as xxxxxxxx.XML file)

Ultimately the question comes down to: is "see calls for pickup" something your really cannot live without? Especially knowing you can do it from the webclient+CSTA deksphone or dialcode/speed dial using * 20 *
 
  • Like
Reactions: Jérôme Wentzel
Hello !

Many thanks for your answer, much appreciated !

Question comes down to: is "see calls for pickup" something your really cannot live without?
-> The answer is that I can't, people will not want to change it, it was working like that on then 20 year old PBX and they do not believe that it is not possible anymore. I can't argue anything against that :(

I understood the concept being the template and the fact that it generates the config file needed by the phone.

I tried different things, but it will not handle the comparaison I need.
If I look in the template file, one if looks like that
{IF sysparam.CUSTOMIZE_QUEUE_RINGTONES=1}

So I tried first with {IF ua=SIP-T27G} that was ok with the phone I have.

I then tried with {IF %%type%%=3140} and {IF type=3140} , 3140 being the number to exclude from the deskphone BLFs. That does not work, I guess it will not generate any configuration to the phone and I guess does not ask to the phone to reload the config file.

I would really appreciate a bit help here...... :)

Details:

this would work
{IF ua=SIP-T27P,SIP-T27G,SIP-T52S,SIP-T53,SIP-T53W}
#Configure Line Key1 hopla
{IF blf1}
linekey.1.line = %%Line%%
linekey.1.value = %%type%%
linekey.1.pickup_value = %%PickupValue%%
linekey.1.type = %%DKtype%%
linekey.1.label = %%type%%
linekey.1.extension = %%PickupValue%%
{IF ua=SIP-T27G}
linekey.1.type = 0
{ENDIF}

{ELSE}
linekey.1.type = 0
{ENDIF}

this won't work

{IF ua=SIP-T27P,SIP-T27G,SIP-T52S,SIP-T53,SIP-T53W}
#Configure Line Key1
{IF blf1}
linekey.1.line = %%Line%%
linekey.1.value = %%type%%
linekey.1.pickup_value = %%PickupValue%%
linekey.1.type = %%DKtype%%
linekey.1.label = %%label%%
linekey.1.extension = %%PickupValue%%
{IF %%type%%=3140}
linekey.1.type = 0
{ENDIF}

{ELSE}
linekey.1.type = 0
{ENDIF}

{IF ua=SIP-T27P,SIP-T27G,SIP-T52S,SIP-T53,SIP-T53W}
#Configure Line Key1
{IF blf1}
linekey.1.line = %%Line%%
linekey.1.value = %%type%%
linekey.1.pickup_value = %%PickupValue%%
linekey.1.type = %%DKtype%%
linekey.1.label = %%label%%
linekey.1.extension = %%PickupValue%%
{IF type=3140}
linekey.1.type = 0
{ENDIF}

{ELSE}
linekey.1.type = 0
{ENDIF}
 
Not, quite - let me see if i can clarify better:

It's more of a "IF values exist, THEN copy them to the config file ELSE do nothing" so it will not be possible to block extension 3140 (or any extension) using this method.

I have another possible solution for you to try which might help prevent people from adding the CEO from the webclient BLF. In the CEO's extension, go to Options tab and use this option:
1595327949030.png

Then make sure no one has the CEO as a BLF assigned ( to remove from anyone that already added it) and then reprovision the phones to reflect the change.

Next time someone tries to add it from their webclient, they will no longer see the CEO extension in the drop down list.
 
Last edited:
VERY GOOD IDEA !

That will solve my problem.
I will add the number in the address book to make sure all have the number.

MUCH APPRECIATED !

Many thanks @JohnS_3CX

giphy.gif
 
  • Like
  • Haha
Reactions: jed and JohnS_3CX
You're welcome!
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur