Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Problem while implementing Data Model Security
raghavyadavm
<p>Hi,</p>
<p> We created a Report which uses a Data Model for which the security is applied for a particular column.When we are testing the Data Security by Running through the Designer, for the user who can access the Report is able to view but for the user's which aren't allowed it is generating an Error "Report render failed".</p>
<p> </p>
<p> We are using the Actuate BIRT Designer Professional Version: 4.4.0 and F-Type Ihub 3.1 (both are the trial version).</p>
<p> </p>
<p> Also we need to know whether Data Model Security and Page Level Security Works for the trial Version of IHub or not.</p>
<p> </p>
<p>Thanks,</p>
<p>Mylagary Raghavender</p>
Find more posts tagged with
Comments
JFreeman
<p>As far as I know, Data Level Security and Page Level Security are both included in the trial releases.</p>
<p> </p>
<p>Regarding the error, could you please provide your designers log file for analysis?</p>
<p>It should be located in the .metadata directory of your designers workspace and will be named .log.</p>
<p> </p>
<p>Also, In the project you provided, I do not see an ACL defined on the Data Set in the .datadesign which leads me to believe it is also not applied to the data model in the generated .data.</p>
raghavyadavm
<p>Hi,</p>
<p> I have applied ACL to the output column CreditLimit in the data set.</p>
<p> </p>
<p> Also i attached the .log file in metadata folder of the workspace.</p>
<p> </p>
<p>Thanks,</p>
<p>Mylagary Raghavender</p>
<p> </p>
JFreeman
<p>Can you attach a new version of the project where you have the ACL in place?</p>
<p> </p>
<p>I cannot reproduce this issue with the ACL set properly.</p>
raghavyadavm
<p>I have attached my Project where i am applying ACL to data set for the Output Column "CreditLimit".I have generated 3 Reports in which i'm testing the Data Model Security,Data set Security and Page Level Security.</p>
<p>When i'm testing the Data Model and Page Level Security Reports for the users which it shouldn't display data it is generating "Report render failed error"</p>
<p> </p>
<p>Also i have attached the Error log file of my designer.</p>
JFreeman
<p>The reason you are getting this error looks to be due to where you have the ACL defined.</p>
<p> </p>
<p>In your data set, you need to move your ACL definition to the "Row Access Control List Expression".</p>
<p>I made this change to your sample project, after which I no longer get any errors with either data or page security.</p>
raghavyadavm
<p>Data security doesn't work for a specific column??</p>
<p>can you please upload the project which you changed!! </p>
JFreeman
<p>Yes, data security does work with a specific column, you just have to create the ACL that points to the desired column.</p>
<p> </p>
<p>Take at look at the attached modified version of your example project.</p>
<p>I have configured the ACL for the country column which means valid entries will be matched to countries listed in the country column. Such as USA, France, UK, etc.</p>
raghavyadavm
<p>suppose i want to display a column country only to "administrator" then what should be the ACL statement and where i need to write it ?either in the Row Access Control list (or) in output Column acl</p>
JFreeman
<p>Gotcha, I had misunderstood previously what you were wanting to do.</p>
<p> </p>
<p>You are correct in that you will want to apply the ACL to the output column in order to prevent data from the entire column based on the ACL. However, it is looking like there may be a bug happening with the ACL applied to the column in a data model.</p>
<p>I can replicate the error:</p>
<p> </p>
<blockquote class="ipsBlockquote">
<p> </p>
<p>The report document stream "QuRs0/TabularCursorData" is not exist. </p>
</blockquote>
<p> </p>
<p>Whereas, using the data set directly looks to limit the data properly without error.</p>
<p>I am doing some more testing/checking on the error but this may end up as a bug report to be resolved in a future release.</p>
<p> </p>
<p>I did find what looks to be a potential workaround for the time being (albeit not as elegant as an ACL on the column itself).</p>
<p>You can read in the ACL supplied at runtime in the visibility expression for the column of the table in the report. Then determine if the column should be hidden or not depending on the values within the ACL.</p>
<p>For example:</p>
<pre class="_prettyXprint _lang-js">
var aclArray = reportContext.getAppContext().get("USER_ACL");
for(var x=0; x<aclArray.length; x++){
if(aclArray[x] == "administrator"){
false;
}else{
true;
}
}
</pre>