Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Mix up of sessions when 15 or more users access BIRT
snowak17
Hi all,
we just performed a stress test on our BIRT Viewer component with 15 participants. The performance was perfectly fine, but what really confused me is the following:
- all the users have a different role / access restriction / attribute which is stored in the user session and set after authentication (LDAP), which is used as a filter than on report level in order to prevent them from seeing data they are not supposed to
- we tested under a scenario with 15 users in parallel in order to perform a stress test and see if performance is fine
- unfortunately under the given scenario the session attribute used for the filter got randomly assigned to people, even under the scenario only one user at a certain point it works perfectly fine
My guess is, that the sessions do not stick with the user, but each time a user logs in, everyone is using the same session and thus having the same attribute for the filter. This is of course absolutely unpleasant, because then the whole access control is lead to be uneffective.
My question is now, how can I ensure that each logged in user remains to be with his session and thus the filter is set correctly for each and every single user logged in at a certain point in time? What are places I can look into, in order to make this work correctly? Any help is highly appreciated.
Thanks for all helpful answers!
Find more posts tagged with
Comments
snowak17
Hi,
I actually was digging a little bit deeper and I kind of understand what is going on, but I do not know how t prevent this from happening.
Here is a short description what is happening:
- when user is logging in, the parameter is added to the session of the current user and taken over by the report --> access control works
- there is a browser cookie set, which has ac_userid anonymous in it, I guess it should have the actual username, in our case email address, but unfortunately is not happening and thus gets lost
- when a second user logs in, first user and second user have the anonymous ac_userid, thus for the first user, also the access parameter is switched to the one for the second user, i guess also sessionid is taken over
That is a very weird thing to happen but I guess it is mostly related to the fact that in the cookie the ac_userid remains anonymous, when a user logs in. My guess. But I am sure, that someone of you has had a similar problem or can tell me, how to set the userid after SSO login to the specific username.
Any help will be very appreciated, because I am definitely stuck here.
Thanks in advance!