Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Controlling Access to View Instances 1

Status
Not open for further replies.

M8tt

Technical User
Feb 11, 2003
43
NL
Hello,

Having just migrated to BOXI I'm in the process of trying to overhaul our BO access/security and enforce row level security on our database for both connections through Universes (webi and CR) and directly to the database (CR).

I have a solution for the Universe part of this: using the 'Enable Datasource Credentials for BO Universes' option I've been able to associate my BO users with seperate db users which I then use in the db to control the data that each user can see.

This works fine but I'm now trying to achieve the same thing for CR's on InfoView with a direct ODBC db connection (as opposed to going through the Universes).

I can force the user to enter db credentials when they schedule a report which can then be used to control the data returned (as for the Universes), although this isn't ideal as I'll end up issuing all users with seperate BO and db log-ins which I'll then have to manage (not a problem for the Universes as the users will never see the db credentials).

But even if I do this I don't seem to be able to find a way to restrict access to the instances; so if user1 and user2 have different rights in the database but can both access the same report and user1 runs an instance there's nothing to stop user2 viewing it and seeing data they shouldn't.

Creating seperate reports and/or folders is one option but we have 200 reports so I don't really want to go this route.

If anyone has any ideas I'd be grateful.
 
There are two advanced settings that I think control this function at the object/folder level -

"View document instances" = Explicitly Denied

"View document instances that the user owns" = Explicitly Granted

Those settings will only allow users to view the results of THEIR OWN instances.

If you want something slicker - that works with Instances that are prescheduled by an ADMIN. You need to set-up different secured folders with fixed-parameter RPTs for each Group, or look at the APOS ViewTime Security add-on tool.

 
Many thanks, those advanced settings should provide the required control. Only snag is it means I'll end up issuing/managing seperate BO and db log-ins but I don't think I'm going to get around that.

Thanks again, Matt
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top