Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Limiting dynamic parameter with Data Row Security
JoeO
Hello,
I have a dynamic parameter (list box) that I would like updated based on data row security so that clients with different credentials can use the same report with parameters specific to their needs. It seems like the list box is populated before data row security is applied and all clients can see all drop down possibilities. If they pick a parameter that they do not have access to, the report is blank, so I know data row security is working-- I just need it to work before they look at the parameter options. Any thoughts?
I am using Actuate 11SP3.
-Joe
Find more posts tagged with
Comments
mwilliams
Is the security level of the user that accesses the report passed through the query, at all? To limit the rows returned?
JoeO
Initially, I had put a filter on a data set that came from my data object, to look at the user name and reference a separate table with all the roles that a user is assigned-- stored independently from the iServer. This would work if my users didn't have access to multiple clients data.
For example, a user can have security roles for two clients (lets say as a contractor), but I want to have the ability to use a report in such a way that if one client wants contractors to see the report, their name will appear in the parameter box, but if another client doesn't want the contractors to see that report, their name will not appear in the parameter box. With my current solution, both names appear in the drop down. When I select the client that does not have a security role for contractor applied to the report design, the report turns up blank. I am glad that the security works on the data, but having the name show up in the drop down seems confusing. The user might think that there is no data for that report, as opposed to the fact that they don't have privileges for that report. I hope this makes sense!
mwilliams
And you can't modify your parameter dataSet's query to filter out clients that do not allow contractors access?
JoeO
I tried modifying the parameter data set, but it doesn't limit the data and I think I have figured out why. The privileges on a report are not related to data row security. The privileges say if a user can see a particular report or not and the data row security looks at the user's ACL (with no regard to the privileges on the report).
With that said, if a report has privileges for at least one role in a user's ACL, that user can view the report. Then, when they run the report, the data security looks at the user's ACL and returns data for all roles they are assigned-- even if the privilege is not listed on the report.
I could probably use some sort of script that compares the data object security to the list of privileges assigned to a report. The only down fall here (if this is even a possibility) is that I would probably have issues with hierarchical roles since the script would only create a string comparison.