Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Security on GlassFish depending on Report
henningp
Hello,
First of all: I'm using birt-3.7.2 on GlassFish 3.1.2 (build 23) and I'm designing with Eclipse-Plugin (BIRT Framework 4.2.1).
Currently I'm trying to restrict the access of my reports only for a few set of users. The access details are stored in a postgres database (Table: reportname, users. e.g. "SampleReport;user1,user2,user3"). I already successful implemented a custom realm which works in basic. But I didn't found a way yet to restrict the access to specific reports. When an user logged in through my custom realm, he got access to all of them (cause the realm only checks for the birt-url and not the get parameter).
Is there an easy way to secure specific reports?
Thanks in advance.
Find more posts tagged with
Comments
kclark
How are the user names passed to the report? You could create a custom parameter page for the user to enter a username and password. Then check the username and pass against the DB. If the information is correct you could possibly send the username information to the report via hidden parameter.
henningp
Hi kclark,<br />
<br />
actually they aren't, that's the problem
. Authentication is currently working through a custom realm on glassfish (only securing the url, not a specific report) and I don't see a way to pass the parameters to the report with this solution.<br />
<br />
Seems your mentioned way is the way I have to go. <br />
1) I will create a preceding jsp-page with a login-form (<del class='bbc'>or is there a birt-feature for "custom parameter page"</del> <- stalking your blog gave me the answer
)?. <br />
<br />
2) Maybe I don't have to pass the username to the report. After successful login there will be a encrypted cookie which stores the access-level for the user. I think I'm able to access the cookies in the reports and check their levels. Using this, there will be no unnecessary logins.<br />
<br />
This should work, thanks for your quick response, kclark. If you have any improvements/corrections don't hesitate