Disable Client Edit is not yet compatible with Blesta 6 - we're working on it.

Disable Client Edit

The Disable Client Edit plugin allows administrators to prevent clients from modifying their account information, ensuring data consistency and compliance.

From £9.99 - View Pricing

Features

What Disable Client Edit gives you

Per-Company Configuration

Configure it independently for each brand on a multi-company install, so every company runs with its own settings.

Fully Translatable

Every staff and client label ships in editable language files, ready to translate into any language or reword to match your brand.

Staff and Automation Are Never Blocked

The locks apply to real client sessions only, so your staff, your API integrations and automated jobs keep updating contact details normally.

All Contacts or Primary Only

Decide whether the locks cover every contact on the account or only the primary contact, so clients can still manage their own additional contacts if you want them to.

Explain the Lock in Your Own Words

An optional message is shown as a notice above the locked fields in the client portal, so clients know to open a ticket instead of wondering why the form will not save.

Read-Only or Completely Hidden

Choose per field whether clients see it greyed out and unchangeable or do not see it at all, so you can either show the value you hold on file or keep the form short and clean.

Import Blesta's Read-Only Fields

Pull a client group's existing read-only contact field list straight into the form with one click, review what it selected, then save. No re-entering settings you already configured.

Different Rules Per Client Group

Set a default lock set that applies everywhere, then give individual client groups their own, so verified, reseller or corporate clients can be treated differently from everyone else.

Lock Any of Twelve Contact Fields

First name, last name, company, title, address 1 and 2, city, country, state, zip, email and phone numbers can each be locked, so the details that matter to your invoices and verification stay exactly as you set them.

Enforced Server-Side, Not Just in the Browser

Locked fields are restored to their stored values on save, so a hand-crafted form submission that bypasses the page cannot change them. Locking the email address also keeps the client's login username from being moved.

Tamper Log

Every reverted change is recorded with the date, client, field, the value that was attempted, the value it was restored to and the source IP address, on its own paginated tab, so you can see who is trying to edit locked details.

Blesta Club Logo

Disable Client Edit

Stop clients changing the contact details you rely on for billing and compliance, with locks that hold even against a crafted form submission.

What it does

Once a client's identity is verified, the last thing you want is for them to quietly change the name, company or email address your invoices and compliance checks depend on. Blesta lets clients edit their own contact details freely, and its built-in "read-only contact fields" setting only goes so far. Disable Client Edit lets you lock any of twelve contact fields per client group, choose whether a locked field is shown greyed out or hidden entirely, and enforces the lock on the server, not just in the browser, so a hand-crafted form submission that bypasses the page cannot change a locked value either.

Key features

  • Lock Any of Twelve Contact Fields: First name, last name, company, title, address 1 and 2, city, country, state, zip, email and phone numbers can each be locked, so the details that matter to your invoices and verification stay exactly as you set them.
  • Read-Only or Completely Hidden: Choose per field whether clients see it greyed out and unchangeable or do not see it at all, so you can either show the value you hold on file or keep the form short and clean.
  • Enforced Server-Side, Not Just in the Browser: Locked fields are restored to their stored values on save, so a hand-crafted form submission that bypasses the page cannot change them. Locking the email address also keeps the client's login username from being moved.
  • Different Rules Per Client Group: Set a default lock set that applies everywhere, then give individual client groups their own, so verified, reseller or corporate clients can be treated differently from everyone else.
  • All Contacts or Primary Only: Decide whether the locks cover every contact on the account or only the primary contact, so clients can still manage their own additional contacts if you want them to.
  • Explain the Lock in Your Own Words: An optional message is shown as a notice above the locked fields in the client portal, so clients know to open a ticket instead of wondering why the form will not save.
  • Import Blesta's Read-Only Fields: Pull a client group's existing read-only contact field list straight into the form with one click, review what it selected, then save. No re-entering settings you already configured.
  • Tamper Log: Every reverted change is recorded with the date, client, field, the value that was attempted, the value it was restored to and the source IP address, on its own paginated tab, so you can see who is trying to edit locked details.
  • Staff and Automation Are Never Blocked: The locks apply to real client sessions only, so your staff, your API integrations and automated jobs keep updating contact details normally.

How this differs from Blesta's built-in read-only contact fields

Blesta already offers a per-group "read-only contact fields" setting, and Disable Client Edit is built to sit alongside it rather than replace it. It adds per-group lock sets with a company-wide default, a hidden mode on top of read-only, a phone-numbers lock, a primary-or-all contact scope, a client-facing explanation message, and a tamper log recording every submission that was reverted server-side. Use the Import from Blesta's read-only fields button to seed the plugin's toggles from Blesta's own setting for the selected group.

Installing and updating extensions can now be done automatically through the Blesta Club Subscription Manager - this is the recommended way going forward.

Blesta Club Logo

Installing Disable Client Edit

Before you start

  • If you are on the leased (subscription) licence, the Blesta Club Subscription Manager must be installed and your subscription active. The owned and owned-source licences have no such requirement.

1. Upload the files

Upload the extension folder into your Blesta installation so it lands under your Blesta directory at:

plugins/disable_client_edit/

For example, on a typical install: /var/www/html/blesta/plugins/disable_client_edit/

2. Install it in Blesta

  1. Log in to your Blesta admin area with a staff account that has the Plugins permission, including Install Plugin and Manage Plugin (found under the Settings group in Manage Staff Groups).
  2. Go to Settings > Company > Plugins and click the Available tab.
  3. Find Disable Client Edit in the list and click Install. Blesta installs it immediately - there's no confirmation step.

3. Configure it

Disable Client Edit needs no API credentials, no cron task and no package or service to work against - it locks fields on Blesta's own client contact forms.

  1. Next to Disable Client Edit in the installed list, click Manage. This opens a Settings tab and a Tamper Log tab.
  2. On the Settings tab, choose a client group from Editing lock set for - "All groups (default)" is the fallback applied to any group without its own set, and each other group can be given its own lock set instead.
  3. For each of the twelve contact fields, choose Editable, Read-only or Hidden.
  4. Under Options, choose whether locks apply to All of the client's contacts or The primary contact only, and optionally enter an explanation clients will see above their locked fields.
  5. Click Submit to save. Repeat for any other client group you want to configure differently.

You're ready to go - see the usage guide for a walkthrough of day-to-day use.

Installing and updating extensions can now be done automatically through the Blesta Club Subscription Manager - this is the recommended way going forward.

Blesta Club Logo

Updating Disable Client Edit

Upgrading works just like installing: upload the new files over the old ones, then run the upgrade from the same page you installed it on.

  1. Back up your current extension files first - good practice before any upgrade.
  2. Upload the new version over the existing folder, replacing the old files.
  3. Log in to your Blesta admin area and go to Settings > Company > Plugins.
  4. Find Disable Client Edit and click Update to run the upgrade.

Version-specific notes

  • v2.0.0: Adds the Hidden field mode, the "Apply locks to" primary-vs-all scope, the client-facing explanation message, the Tamper Log tab and the Import from Blesta's read-only fields button. These are all additive - your existing lock sets keep working exactly as before, and nothing changes until you visit the Settings tab and choose to use the new options.
  • v1.1.0: Corrects the settings table schema and how staff, API and cron edits are told apart from real client edits. The correction runs automatically as part of the upgrade step - no action needed.

Blesta Club Logo

Using Disable Client Edit

For your staff

Settings

Go to Settings > Company > Plugins, find Disable Client Edit in the installed list and click Manage. The Settings tab opens first.

  • Editing lock set for picks which client group you're configuring. "All groups (default)" is the fallback used by any group that has no lock set of its own; pick a specific group to give it different rules.
  • Lock these fields lists all twelve contact fields (First Name, Last Name, Company, Title, Address 1, Address 2, City, Country, State, Zip, Email, Numbers). Each has its own Editable, Read-only or Hidden choice. Read-only shows the field greyed out and unchangeable; Hidden removes it from the form entirely.
  • Under Options, Apply locks to chooses whether the locks cover All of the client's contacts or only The primary contact only - so you can, for example, lock the main account holder's details while leaving additional contacts free to edit their own.
  • Explanation shown to clients (optional) is a short message that appears above the locked fields in the client portal, so clients understand why the form won't let them make changes.
  • Click Submit to save. You'll see "Successfully saved Disable Client Edit settings!" and can switch to another client group to give it its own configuration.

When a specific (non-default) client group is selected, an Import from Blesta's read-only fields button also appears. It pre-ticks the Read-only fields that match whatever Blesta's own per-group "read-only contact fields" setting already has for that group, so you don't have to re-enter them by hand - review the pre-ticked selections, then click Submit to apply them.

Tamper Log

Click the Tamper Log tab to see every locked-field change that a client attempted and that was reverted server-side: the date, the client, the field, the value they attempted, the value it was restored to, and their IP address. This table lists every reverted attempt across all client groups and grows over time - it is not pruned automatically.

For your clients

Locked fields appear on the client's own Manage Account page (their name, company and contact details) and on their Contacts page (any additional contacts on the account, when locks are set to apply to all contacts rather than the primary contact only):

  • A Read-only field is shown greyed out; clients can see the value but not change it.
  • A Hidden field, and its label, does not appear on the form at all.
  • If you set an explanation message, it appears as a notice above the form.
  • Saving the form still reports success even where a locked field was present - the value the client sees does not change, because the field was never editable in the first place.

Staff edits, API calls and cron jobs are never affected by any of this - the locks only apply when a client is editing their own details.

Good to know

  • The Tamper Log only records an attempt when a locked field's submitted value actually differs from what's stored - an honest save that never touches those fields logs nothing.
  • Locking the Email field also protects the client's login username: if a client's username is their email address, it's restored along with the reverted email value.
  • The Tamper Log has no built-in cleanup. If you expect a high volume of blocked attempts, periodically clear old entries from the log yourself.

v2.0.0 - 2026-09-11

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Per-client-group lock sets with a company-wide default. Optional "why is this locked" client hint. Tamper audit log of reverted client edits, viewable on the manage screen. Primary-vs-all contact scope toggle. Per-field Editable / Read-only / Hidden mode. One-click import of Blesta's own read-only contact fields. A locked phone-numbers field is now also enforced when a client creates a new contact, not only when they edit an existing one.

v1.0.0 - 2024-09-22

PHP 7.2 - 7.3, 8.1 - 8.4 · Blesta 5.x

Blesta Club release

Pricing Options

Get exactly what you need and want.

Requires PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Included In

Value: £42.3

£14.99
per month
  • +51 Other Extensions
  • Additional Discounts
  • Included Support & Updates
Leased
£9.99
per year
  • Partially Encoded
  • Full Functionality
  • Included Support & Updates
Owned
£30
one time
  • Partially Encoded
  • Buy Once Use Forever
  • 1 Year Support & Updates
Owned - Source
£60
one time
  • Source Available
  • Buy Once Use Forever
  • 1 Year Support & Updates

Not sure whether to lease or own? Our FAQ explains how the licence types differ.

Reviews

What our customers say

(0 customer reviews)

Seems like this extension doesn't have reviews yet...
Be one of the firsts to leave a review!

It is possible to leave a review only if you have purchased this extension or a Club tier which contains it.
We reserve the right to alter wording or formatting for presentation.
We will discuss any changes made and offer the option to withdraw review text if the changes can't be agreed on.
It may take up to 1 hour for a review to appear or update due to caching.

You might also like

More extensions to explore

Blesta 6

Plugin

Announcements

(1)

Integrate the Announcements plugin to provide updates and news to your clients.

PHP 8.2 - 8.4 · Blesta 6.x

Blesta 6

Plugin

Bulk Download Invoices

Download multiple invoices simultaneously.

PHP 8.2 - 8.4 · Blesta 6.x

Blesta 6

Plugin

Convoy Automatic Stock

Automate Convoy stock management.

PHP 8.2 - 8.4 · Blesta 6.x

Blesta 5

Plugin

Cookie Cuttr

Implement cookie compliance easily.

PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x

Blesta 6

Plugin

Credit Awards

Give your clients rewards based upon service purchases.

PHP 8.2 - 8.4 · Blesta 6.x

Blesta 6

Plugin

Crisp Live Chat

Integrate Crisp live chat into your client area.

PHP 8.2 - 8.4 · Blesta 6.x