Troubleshooting the Laserfiche Apps

Laserfiche Forms App

Notifications

If notifications are not working correctly, the notification service may have restarted. To restore notifications, either:

  • Turn Notifications off and back on in Settings
  • Close and reopen the app.

Either action re-registers the app for notifications.

Biometric Authentication Limitations

When biometric authentication is enabled, the Laserfiche Forms app signs users in using a secure Laserfiche user key instead of redirecting them to their identity provider (IdP) for every sign-in. As a result, some identity provider features and user updates are not applied until the user signs in through the IdP again.

User information may not be up to date

If you use SAML authentication and SCIM is not configured, the following information may not immediately reflect changes made in your identity provider:

  • User name
  • Email address
  • Group membership

This occurs because these attributes are normally refreshed when the user authenticates through the identity provider.

If you use SCIM for user provisioning, these updates are synchronized automatically. However, because SCIM synchronization is not instantaneous, there may be a brief delay before changes appear in the app.

Identity provider policies are not enforced

When signing in with biometrics, users bypass the identity provider's sign-in page. Because of this:

  • Identity provider sign-in policies (such as location restrictions or geofencing) are not evaluated.
  • Biometric sign-ins are not recorded in the identity provider's sign-in history or audit logs.

Refreshing user information

To retrieve the latest user information from your identity provider, sign out of the app and sign in again. This forces a full authentication through the identity provider.

Workarounds

If these limitations are a concern, consider one of the following options:

  • Configure SCIM to synchronize user and group information automatically.
  • Use your identity provider's biometric authentication solution (such as Okta FastPass), when supported.
  • Disable app-side biometric authentication and sign in through your identity provider each time.

User Key Renewal

When biometric authentication is enabled for Laserfiche Cloud, the app uses a secure user key to authenticate users. The user key is valid for up to 30 days and can be renewed automatically without requiring users to sign in again.

How renewal works

When you sign in with biometric authentication, the app checks whether your user key is still valid. If the user key is valid, biometric sign-in continues normally. If the user key has expired, the biometric sign-in cannot be completed. The sign-in page is displayed, and you must enter your credentials to authenticate. A new user key is then issued.

The app can also renew the user key before it expires to extend its validity for another 30 days. Renewal can occur when:

  • You sign in with biometric authentication using a valid user key.
  • Biometric authentication is enabled, but you sign in manually using your username and password.

Renewal frequency

To minimize unnecessary network requests, the app checks for user key renewal at most once per day. This renewal process has minimal impact on sign-in performance.

Troubleshooting expired user keys

If biometric sign-in no longer works, your user key may have expired.

Resolution:

  1. Sign in using your username and password.
  2. If biometric authentication is enabled, a new user key is issued automatically.
  3. Future biometric sign-ins will continue to work for up to 30 days, provided the key remains valid or is renewed automatically.