We used the following approach to only allow authorized users to access a report.<br />
<br />
First our application sets a session cookie (named: OUR_REPORT) that contains a md5 hash code. This hash code was generated on the following example string: "sample_report.rptdesignmikey22" (report name+user name+hour)<br />
<br />
The url that calls the birt report contains the standard parameters and an additional one we called __user:
http://somehost/birt/frameset?__showtitle=false&__report=sample_report.rptdesign&Customer=2&Week=2009-02&__user=
mikey<br />
<br />
Within the BIRT report we read the report name (sample_report.rptdesign) and the user (mikey) from the URL. Together with the current hour we create a md5 has code within BIRT. Now we read the md5 hash code from the session cookie and compare it with our own md5 hash. If they are equal we set our access_flag variable to 0, otherwise we set it to 1.<br />
<br />
In the report itself the visibility of objects depends on the flag: if flag=1 we hide all output and show a text indicating the user has no access.<br />
<br />
This approach prevents users to access reports by simply changing the URL to something else (i.e. change the user). The example described uses hour as a variable component, but one could look for other variables as well.<br />
<br />
This is the script we added to the BeforeFactory of the report:
importPackage( Packages.javax.servlet.http );
var request = reportContext.getHttpServletRequest();
var cookies = request.getCookies();
var flag = 0;
var cookiestring="";
var tm = new Date();
hour = tm.getUTCHours().toString();
prev_hour = (tm.getUTCHours()-1).toString();
//if the hour is one digit, we need to add a leading 0 because this is also used in PHP
if (hour.length==1) {hour='0'+hour};
if (prev_hour.length==1) {prev_hour='0'+prev_hour};
//search for the correct cookie, being OUR_REPORT
for (i=0; i< cookies.length; i++)
{
if(cookies[i].getName().equals("OUR_REPORT")){
cookiestring=cookies[i].getValue();
}
}
//read the url values
var request = reportContext.getHttpServletRequest();
user=request.getParameter("__user");
repname=request.getParameter("__report");
urlstring=md5(repname+user+hour);
prev_urlstring=md5(repname+user+prev_hour);
//set the flag to allow the report components to hide if flag=1 (= no access)
if (cookiestring!=urlstring)
{
if (cookiestring!=prev_urlstring) {flag=1}
};
reportContext.setGlobalVariable('access_flag', flag);
<br />
Finally to make this work we added the attached MD5.js script to the resources of the BIRT report.