Skip to main content

#Appexchage Apps18 utenti parlano di questo argomento

Hello. I'll be using UTAM for our Automation Framework.     For the setup, I did install the following:      1. Install UTAM  npm i utam      2/ INSTALL WDIO  npm init wdio    3. INSTALL UTAM WDIO SERVICE  npm i wdio-utam-service --save-dev    4. INSTALL DOTENV  npm install dotenv    4. INSTALL SALESFORCE PAGE OBJECTS  npm i salesforce-pageobjects    5. ADD UTAM AS DEV-DEPENDENCY  npm add --dev utam    6. ADD BUILD to package.json      "test:ui:compile": "utam -c utam.config.js",      "test:ui:generate:login": "node scripts/generate-login-url.js",      8. Add UTAM in wdio.config.js  require('dotenv').config();  const { UtamWdioService } = require('wdio-utam-service');    services: [          [              UtamWdioService,              {                  implicitTimeout: 0,                  injectionConfigs: ['salesforce-pageobjects/ui-global-components.config.json'],              },          ],      ]    -----------  However, whenever I run the test, it's still giving me either a reference error of "utam is not defined" or the import modules (e.g. import {DesktopLayoutContainer} from '/salesforce-pageobjects/dist/navex/pageObjects/desktopLayoutContainer' cannot be found'    I tried uninstalling and installing the node_modules and tried everything in https://www.geeksforgeeks.org/node-js/how-to-resolve-a-cannot-find-module-error-using-node-js/ and     What am I missing?   

1 risposta
  1. 21 gen, 11:40

    Hi @Aira Gutierrez

     

    The "UTAM not defined" and module import errors in 2026 typically stem from missing compiler generation steps or an incomplete link between your testing environment and the generated code.

    1. Resolve "UTAM is not defined"

    In 2026, the global utam object is not provided by default in standard Node.js scripts; it must be imported or generated via the compiler.

    • Ensure Compilation: Your wdio.config.js and tests depend on JavaScript files that are compiled from .utam.json files. Run the compiler command you added to your package.json:

    npm run test:ui:compile

     

    • Manual npx check: If the script fails, try running it directly to see specific error messages:

    npx utam -c utam.config.js

     

    • WDIO Global Hooks: Ensure your wdio.config.js properly exports the UtamWdioService. If you are trying to use utam in a test script, you must use the utam object injected by the service. In your test file, you typically don't import a global "utam"; you use the browser object or the injected loader: 

      javascript-

    // Instead of calling a global utam 

    const loader = browser.utam; // The service adds this to the browser object 

     

    2. Fix "Module not found" for Salesforce Page Objects

    The salesforce-pageobjects package contains JSON definitions that must be compiled into JavaScript before they can be imported. 

    • Correct Import Paths: In 2026, the standard package structure for salesforce-pageobjects does not always require the /dist/ path in the import string. Try importing from the package root: 

      javascript-

    // Use this 

    import { DesktopLayoutContainer } from 'salesforce-pageobjects/pageObjects/desktopLayoutContainer'; 

    // Instead of 

    import { DesktopLayoutContainer } from '/salesforce-pageobjects/dist/navex/...';

     

    • Update Package Version: Ensure you are using a version compatible with the current Salesforce release (Winter '26). Check for updates:

    npm install salesforce-pageobjects@latest --save-dev

     

    • Check utam.config.js: Ensure your configuration file explicitly lists salesforce-pageobjects in the injectionConfigs. An empty or missing configuration will prevent the generator from finding the Salesforce definitions. 

    3. Verify WebDriverIO Configuration

    If you recently upgraded to WebDriverIO v8 or v9 (standard in 2026), ensure your wdio.conf.js is using the newer object-based service definition. 

    • Service Configuration: Ensure the UtamWdioService is properly imported and added: 

      javascript-

    const { UtamWdioService } = require('wdio-utam-service'); 

    exports.config = { 

        // ... 

        services: [ 

            [UtamWdioService, { 

                implicitTimeout: 0, 

                injectionConfigs: ['salesforce-pageobjects/ui-global-components.config.json'] 

            }] 

        ], 

    };

     

    Final Troubleshooting Step: If imports still fail, check your node_modules folder manually to confirm the file path salesforce-pageobjects/pageObjects/desktopLayoutContainer.js exists. If only .json files exist there, the package was not compiled correctly.

0/9000
Josh Wiseman ha fatto una domanda in #Dashboard Pal

Our org is looking to upgrade any installed packages that still have components on an API version below 45.0. One of the last ones we have is Dashboard Pal, which is a Salesforce Labs app. 

 

The latest version v2.6.0 (last updated on the appexchange on 01/09/2023) still has some components on API versions below 45.0. 

 

Is there anyone I can contact about these Salesforce Labs apps? I can't see any support email on the appexchange listing. Failing that, does anyone happen to have an alternative app to Dashboard Pal that offers similar functionality? 

 

#Dashboard Pal  #Appexchage Apps

0/9000

Looking for an AppExchange Security Review specialist consultant. Have pen-test commissioned, full SR docs drafted, targeting June 9 submission. Need questionnaire support + reviewer liaison. Budget confirmed, need to start this week. DM me.   

1 risposta
  1. 29 set, 07:10

    Hi Anuj!

    For an AppExchange Security Review, having the pen-test and documentation already prepared should give you a good starting point. For the remaining work, I’d look for someone who has hands-on experience with Salesforce’s security review questionnaire, code/security remediation, and the reviewer communication process. 

     

    It may also be worth having the consultant do a pre-submission review of the package and security documentation before the June 9 submission, so any gaps can be addressed beforehand. 

     

    If anyone here has recently supported an AppExchange Security Review end-to-end, their experience with the questionnaire and review process would be especially useful for Anuj.

0/9000

We are in security review for our AppExchange solution. Our app is an external SaaS that uses a single partner-owned OAuth app; subscribers authorize it via the OAuth 2.0 web-server flow (Authorization Code + PKCE), and the app is NOT installed into subscriber orgs.   

The reviewer asked us to either package an External Client App (ECA) within the managed package or justify not doing so, and to enable four controls: PKCE, Refresh Token Rotation, IP allowlist for refresh token redemption, and Refresh Token Rotation Idle Timeout.   

Could you please confirm:   

  1. For a partner-owned app that is not installed in subscriber orgs, is it acceptable to NOT package it and instead provide a justification?
  2. Can the four mandated OAuth controls be applied on our existing **Connected App**, or is migration to an **External Client App** required?

 

Thank you.   

1 risposta
  1. 28 set, 17:36

    Hi Aron!

    Based on Salesforce’s current AppExchange security-review guidance, your use case appears to fall under the packaging requirement.

    For an Authorization Code/Web Server flow where the callback URL is controlled by the ISV partner, Salesforce currently lists the integration as requiring packaging. The fact that the SaaS application itself isn’t installed in subscriber orgs doesn’t by itself remove that requirement. 

     

    Also, Salesforce is moving new integrations toward External Client Apps (ECA). Existing Connected Apps can continue to operate, but Salesforce recommends ECAs for new integrations. 

     

    So I would clarify with the reviewer whether they specifically require the existing Connected App to be migrated to an ECA, rather than assuming the four requested controls can all be enabled on the existing Connected App. Salesforce documents ECA-specific OAuth security controls such as refresh-token rotation and IP restrictions.

    For the security-review response, I’d also explicitly describe your OAuth flow, who owns the callback URL, where refresh tokens are stored, and how PKCE/refresh-token protection is implemented. That should make it easier for the reviewer to confirm the expected configuration.

0/9000

Summary  A 2GP managed-package External Client App (ECA) installs successfully in a subscriber org, but the OAuth 2.0 web-server flow from that subscriber org fails at authorization with:  error=OAUTH_AUTHORIZATION_BLOCKED  error_description=Cross-org OAuth flows are not supported for this external client app  We are migrating from a Connected App (which worked cross-org) to a packaged ECA due to the Connected App deprecation. We need to know what configuration allows subscriber orgs to complete OAuth authorization against our packaged ECA.    Environment  - Packaging / Dev Hub org: jeff.qiu.c0c4028cfddb@agentforce.com — Org Id 00Dg500000CfSJBEA3  - Managed package (2GP): coachpilot-sf-eca, package Id 0Hog50000000piTCAQ, namespace cpsftest  - Package version: 04tg50000009p05AAA (0.1.0.1) — Released = true  - External Client App CoachPilotSF: distributionState=Packaged, Status Enabled, scopes Api, RefreshToken, callback https://staging-api.coachpilot.com/api/v1/crm/salesforce/callback, PKCE (S256), oauthLink → 00Dg500000CfSJB:888g5000000Z6k5  - Consumer key (unchanged after packaging): 3MVG9QJ.PEcC...  - Model: external SaaS backend runs the OAuth web-server flow using the single Dev Hub consumer key across all subscriber orgs.    Steps to reproduce  1. Subscriber installs released package 04tg50000009p05AAA — succeeds (ECA present, DistributionState=Packaged).  2. Subscriber ECA policy set to "All users may self-authorize".  3. OAuth web-server authorize from the subscriber's own My Domain: https://.my.salesforce.com/services/oauth2/authorize?response_type=code&client_id=<Dev Hub consumer key>&redirect_uri=<callback>&scope=api%20refresh_token&code_challenge=<...>&code_challenge_method=S256  4. Result: redirected with OAUTH_AUTHORIZATION_BLOCKED — Cross-org OAuth flows are not supported.    Already confirmed (no need to re-check)  - Package version Released (not beta); subscriber install succeeds; ECA DistributionState=Packaged.  - Subscriber policy = "All users may self-authorize".  - Consumer key = Dev Hub ECA's, unchanged.  - Authorize attempted from the subscriber's own My Domain AND from login.salesforce.com — both blocked; the flow reaches the consent page, block is at grant.    Cannot inspect (suspected cause)  - The Dev Hub ExtlClntAppGlobalOauthSettings (global OAuth settings) — not retrievable via Metadata API source, describe empty via Tooling API, not editable in UI. Suspect a required cross-org/distribution "trust" setting on the global OAuth settings.    Questions  1. For a packaged ECA (2GP), what config on the packaging org's global OAuth settings (ExtlClntAppGlobalOauthSettings) lets subscriber orgs complete the web-server OAuth flow using the packaging org's consumer key?  2. Is Cross-org OAuth flows are not supported expected when a subscriber (with the package installed) authorizes using the packaging org's consumer key? What is the supported ISV pattern?  3. Must each subscriber generate their own global OAuth settings (per-subscriber consumer key)? If so, how does the external backend obtain each org's consumer key programmatically?  4. Any limitation with the packaging org being an @agentforce.com (trial/dev) org type for cross-org ECA OAuth distribution?    Desired outcome  Customer installs the managed package, authorizes via OAuth web-server flow, and our backend receives that org's access/refresh tokens — the Connected App experience, via ECA.    

1 risposta
  1. 28 set, 12:31

    Hi Jeff!

    Your setup looks close to the supported packaged-ECA model. Salesforce documents that a packaged External Client App can either generate its own OAuth global settings in the subscriber org or reference the global OAuth settings from the source/packaging org. In the latter model, the subscriber ECA’s OAuth link should reference the source org and its consumer ID. 

     

    So I wouldn’t expect the subscriber to automatically need a separate consumer key just because the package is installed. Salesforce specifically documents the source-org global-settings association for OAuth. 

     

    One thing I’d verify is the actual ExtlClntAppOauthSettings OAuth link in the installed subscriber app and confirm it points to the source org/global OAuth settings exactly as documented. If the subscriber instead has its own global settings, then it will have its own OAuth consumer credentials. 

     

    Also, the source org needs to remain available because subscriber ECAs that reference its global OAuth settings depend on that source configuration. 

     

    Given that your OAuth request is reaching the consent page and then specifically fails with OAUTH_AUTHORIZATION_BLOCKED, I’d focus on the ECA association/global OAuth configuration rather than the subscriber policy alone. 

     

    If you can share the ExtlClntAppOauthSettings OAuth link value from the packaged ECA/subscriber, that would be the next thing I’d check.

0/9000

Hi everyone,

We are preparing an external API / web application integration for our AppExchange Security Review. The review team will need to test our API endpoints from their automated scanning suites and dynamic networks.

Our main operational blocker right now is MFA and Device Activation (OTP). Because our team does not have personnel available on standby 24/7 to instantly provide multi-factor authentication access codes or email OTP tokens to the reviewers, we need an entirely hands-off authentication architecture for our test environment.

Given Salesforce’s strict platform enforcements restricting traditional UI MFA bypass permissions, what is the current accepted practice for API apps?

My Questions:

  • If we provision a dedicated Salesforce Integration User license (which uses API-only tokens/OAuth instead of interactive UI login), does the Security Review team's automated testing suite natively support this without triggering an MFA or Device Activation challenge?
  • If the review suite requires standard user credentials that trigger an unexpected email OTP, how are partners managing this asynchronously without a 24/7 live operations team to hand over codes?

We want to make sure we architect our authentication flow correctly so that the submission doesn't fail pre-queue validation due to a missed MFA prompt. Any advice from recent submitters would be huge. 

 

#Appexchage Apps

 

 

#Security Review  #Agentforce

1 risposta
  1. 22 set, 05:44

    For an AppExchange Security Review, I’d avoid designing around the assumption that an API-only user automatically bypasses every authentication control. The safer approach is to confirm the current review-team requirements for integration credentials and test the exact OAuth/API flow in the submitted environment beforehand. If automated scanners require interactive authentication, Salesforce Partner Support or the Security Review team should clarify the supported testing arrangement rather than relying on manual OTP handling.  Visit here for more information.

0/9000

   

Subject: Link Namespace fails: invalid_request "missing required code challenge" 

    

   Dev Hub org ID: <xyz>. Namespace org ID: <abc>. Namespace: Nativesign. 

   Namespace Registries > Link Namespace popup returns error=invalid_request&error_description=missing required code challenge. 

   The connected app "SalesforceDX Namespace Registry" has PKCE checked and locked ("contact Support"). Org-level PKCE is OFF. How can I link my namespace? 

 

#Package Manager  #Appexchage Apps  #Generation Managed Package  #Installed Packages

1 risposta
  1. 21 set, 13:54

    This looks like a mismatch created by Salesforce's own PKCE enforcement rollout rather than something wrong in your org's configuration. The SalesforceDX Namespace Registry connected app is a Salesforce-owned system connected app used by the Namespace Registries Link Namespace flow, and its PKCE requirement is locked because Salesforce has been moving connected apps and External Client Apps toward mandatory PKCE, with no admin opt-out on system apps like this one. Your org-level Require PKCE toggle being off is not relevant here, since that setting only affects apps that inherit the org default, and this one has its own requirement baked in. 

     

    The "invalid_request / missing required code challenge" error means the client side of this OAuth exchange, the Link Namespace popup itself, is not sending a code_challenge parameter even though the connected app now demands one. Since that popup is Salesforce's own UI and not something you control from Setup, you cannot fix this from your Dev Hub or Namespace org settings. Other admins have hit the same "missing required code challenge" wall on various Salesforce-owned OAuth flows since PKCE enforcement tightened, so this is worth logging as a Salesforce Support case, quoting the exact error and the Dev Hub and Namespace org IDs, so they can confirm whether it is a tracked regression tied to the PKCE rollout on that specific connected app. 

     

    Background on PKCE enforcement:

    https://help.salesforce.com/s/articleView?id=005316703&language=en_US&type=1

     

     

    Assumption: I cannot reproduce your Dev Hub, so I cannot fully confirm this is a Salesforce-side defect versus something specific to your org's Namespace Registry setup. This is inferred from the well-documented PKCE enforcement pattern and other reports of the same error on Salesforce-managed connected apps once PKCE became mandatory without an opt-out.

0/9000

I am in the process of submitting our package for AppExchange listing. Our solution is completely free to use, and we are preparing it for the Security Review.

However, during the submission process, the system is displaying a $999 security review fee, even though our listing is a free solution. As per Salesforce documentation and common guidelines, free solutions are generally exempt from this security review fee.

Could you please confirm:

  1. Whether the $999 fee is mandatory even for free AppExchange solutions.
  2. If free apps are exempt, please guide us on the exemption process or any steps required to correctly classify the solution so the fee does not appear.

We want to ensure the listing process is followed correctly and would appreciate your guidance on how to proceed.   

5 risposte
  1. 20 nov 2025, 09:50

    @Usman Khan

     

    You might be right, but in my last communication with the Security Review team, they clearly mentioned that we need to have the waiver code.  

    @Shubham Gour

    Please keep us update; As Usman suggested please raise a case from your partner account.  

     

0/9000

We are looking for a native salesforce application which can replace eventbrite and help us in event management and ticketing for gardens .  

 

#Appexchage Apps

1 risposta
  1. 2 set, 19:19

    Hi @Janaki Reddi

     

    A few native options actually cover garden style ticketing well timed/dated admission tickets, guest checkout (no login needed for buyers), and Salesforce native data (no sync lag or external ticketing database). Here's how the leading ones stack up:

     

    A consultant's take: for garden admission/event ticketing specifically, my starting pick would be Blackthorn Events it's the most mature native option, handles payment processing and refunds itself (no separate Stripe/PayPal integration to maintain), and pairs with Experience Cloud for a public-facing ticket storefront visitors can buy from without a login. It's also the one most gardens/botanical orgs and nonprofits already use, per the vendor's own case data. 

    Two things worth confirming before you commit, since they change the recommendation: 

    • Ticket volume/pattern is this timed/dated admission (e.g. "Saturday 10am garden entry") with capacity caps, or more traditional single events (fundraisers, classes, weddings)? Blackthorn and AC Events both handle capacity based timed tickets; EventSpark leans more toward simple RSVP/registration.
    • Budget tier Blackthorn is licensed per-org and sits mid-to-high; EventSpark is the lower cost native option if this is a smaller garden with modest ticket volume.

    If you want, I can pull current AppExchange reviews/pricing details for whichever one fits your volume, or scope out what a native build/config would take if you'd rather not add a managed package at all worth knowing that's also an option here, since garden ticketing with capacity limits is buildable on standard Salesforce (Flow + Experience Cloud + a payment gateway like Stripe) if you want full control instead of a packaged app. 

     

    I hope you find the above information helpful. If it does, please mark it as Best Answer to help others too.

0/9000

Hello, 

 

I have set up the Enhanced Field History Tracking. I mapped it to a custom object I built and have set up the flow but it currently is not creating the records in the custom object I built. I am not sure were the error is.  

Salesforce Labs Enhanced Field History Tracking

 

Enhanced Field Flow.png

 

Debug Enhanced.png

 

 

 

#Appexchage Apps

3 risposte
  1. 28 ago, 21:44

    BINGO!!!  Once I learned a little Apex, I was able to get it working.  Thanks for the insight.

0/9000