Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - openCoreEMR/oce-cli-manage-users: OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR · GitHub
Skip to content

Repository files navigation

oce-cli-manage-users

Standalone PHP CLI for managing OpenEMR users — what bin/console openemr:user would be if it existed upstream. Designed for operators bringing up an account on a freshly-restored database dump, and for general user administration across forks (vanilla openemr/openemr, openemr-internal, customer forks).

Distributed as a single PHAR. Runs against any OpenEMR install from rel-702 through master.

Privileges. This CLI writes directly to the users and users_secure tables (and the gacl_* / groups tables when registering group membership). It bootstraps OpenEMR with $ignoreAuth = true and deliberately bypasses the OpenEMR ACL — there is no logged-in user and no permission check. Run it only as an operator who already has DB write access to the OpenEMR site, and treat each invocation the same way you'd treat direct SQL against those tables.

Install

Grab the PHAR from the latest release and drop it next to (or inside) the OpenEMR install:

curl -L -o oce-manage-users.phar \
https://github.com/opencoreemr/oce-cli-manage-users/releases/latest/download/oce-manage-users.phar
chmod +x oce-manage-users.phar

Or install from source for development:

git clone https://github.com/opencoreemr/oce-cli-manage-users
cd oce-cli-manage-users
composer install
./bin/oce-manage-users list

To smoke-test the CLI against a real OpenEMR install in Docker:

task tools:install # one-time: pulls openemr/openemr into tools/openemr/vendor
task dev:start # bring up openemr + mysql + phpmyadmin (random loopback ports)
task dev:port # show the assigned host port
task exec -- user:list # run any CLI subcommand inside the container

The CLI source is bind-mounted into the container at /var/www/localhost/htdocs/openemr/oce-cli-manage-users, so edits on the host are reflected immediately. See Taskfile.yml for the full task list.

Usage

Every command takes:

OptionDefaultNotes
--openemr-path=<path>/var/www/localhost/htdocs/openemrPath to OpenEMR root (must contain interface/globals.php)
--site=<name>defaultOpenEMR site (sites/<name>/sqlconf.php)

user:reset-password

Set or randomize a user's password.

# Prompt for the new password
oce-manage-users.phar user:reset-password --user=admin
# Provide it on the command line (visible in process list — prefer prompt or --random)
oce-manage-users.phar user:reset-password --user=admin --password='hunter2'# Generate a random password and print it once to stdout
oce-manage-users.phar user:reset-password --user=admin --random

Updates users_secure.password, stamps last_update_password = NOW(), and clears login_fail_counter and auto_block_emailed.

user:create

Create a new user.

# Authorized provider — defaults to the Administrators ACL group.
oce-manage-users.phar user:create \
--username=alice \
--password='sekret' \
--firstname=Alice \
--lastname=Liddell \
--email=alice@example.com \
--authorized \
--active
# Non-authorized user — must specify at least one --group.
oce-manage-users.phar user:create \
--username=bob \
--password='sekret' \
--firstname=Bob \
--lastname=Brown \
--group=Clinicians
# Multiple groups — repeat --group.
oce-manage-users.phar user:create \
--username=carol \
--password='sekret' \
--firstname=Carol \
--lastname=Carter \
--group=Administrators \
--group=Clinicians

Defaults: --active is on, --authorized is off. Inserts into users and users_secure, backfills users.uuid if OpenEMR\Common\Uuid\UuidRegistry is available, and performs both group registrations OpenEMR's auth flow requires:

  • gAcl (gacl_aro + gacl_groups_aro_map) via AclExtended::setUserAro, controlled by --group=<title> (repeatable). Required unless --authorized is set, in which case it defaults to Administrators.
  • Legacy groups table (the flat (name, user) mapping read by UserService::getAuthGroupForUser during auth) via --legacy-group=<name> (default Default). The auth flow rejects login with the same error=1 redirect when this row is missing, even with a correct ACL ARO — it's a separate, older grouping system that OpenEMR still consults.

Without both registrations the user has a valid credential but cannot log in.

user:list

List users as a table.

oce-manage-users.phar user:list
oce-manage-users.phar user:list --active-only
oce-manage-users.phar user:list --inactive-only
oce-manage-users.phar user:list --locked

Columns: id, username, fname, lname, active, authorized, last_update_password, login_fail_counter.

user:activate

Set users.active = 1. Optionally also set users.authorized = 1.

oce-manage-users.phar user:activate --user=alice
oce-manage-users.phar user:activate --user=alice --authorized

Idempotent.

user:unlock

Clear the lockout counter.

oce-manage-users.phar user:unlock --user=alice

Sets users_secure.login_fail_counter = 0, last_login_fail = NULL, auto_block_emailed = 0. Idempotent.

Running against a docker compose stack

For an existing stack of your own, copy the PHAR into the OpenEMR container and exec it:

docker compose cp oce-manage-users.phar openemr:/tmp/oce-manage-users.phar
docker compose exec -T openemr php /tmp/oce-manage-users.phar user:list

Or mount it into the container via a compose.override.yml:

services:
openemr:
volumes:
- ./oce-manage-users.phar:/usr/local/bin/oce-manage-users.phar:ro

For local dev/iteration on this CLI itself, use the bundled task dev:start workflow described above — it brings up OpenEMR's development-easy stack with the CLI source bind-mounted in.

Compatibility

Designed and tested against OpenEMR rel-702 through master. The only OpenEMR APIs this CLI touches are:

  • interface/globals.php (bootstrap)
  • OpenEMR\Common\Auth\AuthHash::passwordHash() (password hashing — same signature in 7.2 and master)
  • OpenEMR\Common\Uuid\UuidRegistry (if present — graceful fallback if not)
  • sqlQuery, sqlStatement, sqlInsert, sqlFetchArray (since pre-7.0)

No dependence on bin/console, OEModule autoload, or anything that varies between forks.

Out of scope (for now)

  • ACL groups, users_facility, MFA management — separate commands later
  • LDAP / external auth backends
  • Bulk operations (CSV, etc.)
  • Wrapping the CLI in a docker image

License

GPL-3.0-or-later.

About

OpenEMR CLI tool for managing users (create, reset password, activate, unlock), by OpenCoreEMR

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages