Open Source BI Helical Insight has reintroduced canned reporting module from version 6.0 onwards. We have already covered how canned reports can be created. Once a report is created, it is very important that people get to see their own dataset only.

Introduction: In this blog we are going to explain how to implement data security based on the logged-in user’s name. We have created a report having the data of employee details.

In this example, we want to filter the data based on the logged-in user. If the user logs in as hiadmin, they can see all the data. Other users can see only their own data. This ensures proper data security, allowing admin full access while restricting regular users to their own data. You can read about the user role management here. User roles creation can happen via the user role module of Helical Insight, or it can also be setup automatically via SSO as well.

Please make sure you have gone through the blog “Introduction to Canned Reporting Interface“.

In Canned Report 6.0, data security can be implemented using two approaches: Groovy Managed Connection and Groovy Plain JDBC Connection.
In this documentation, we will focus on Groovy Managed Connection, as it is the recommended approach.

Steps to implement Data Security

  1. Create a data source connection using the data sources module. Once you have created a datasource, it will dynamically create a connectionId (like show in the below image). Read more about creating datasource here.
    https://www.helicalinsight.com/adhoc-datasource/

    In our use case, we created a Derby connection, and the connection ID is 1

  2. Implementing Data Security In Canned Reports Based On Logged In User Name

  3. Next we need to create a Groovy Managed Connection. For that, go to the Data Source page, open the Advanced section, and choose Groovy Managed JDBC DataSource. Refer to the screenshot below

    Implementing Data Security In Canned Reports Based On Logged In User Name

    Click on Create. This opens the UI displaying the following fields: Datasource Name, Location, and a Groovy placeholder. The Groovy placeholder comes with some default code provided as a reference

    Implementing Data Security In Canned Reports Based On Logged In User Name

    We created a Groovy connection with the datasource name Canned Report DS, provided the code below, and then saved the connection

    import net.sf.json.JSONObject;
    public JSONObject evalCondition() {
        JSONObject responseJson = new JSONObject();
        responseJson.put("globalId", 1);   // Put the connection ID which we get from step1
        responseJson.put("type", "global.jdbc");
        return responseJson;
    }
    
  4. Implementing Data Security In Canned Reports Based On Logged In User Name

  5. Open the Canned Report module. By default, it opens as shown below.

    Implementing Data Security In Canned Reports Based On Logged In User Name

    Click on Add Connection at the top right, select Groovy Managed connection. Here, we selected Canned ReportDS. Canned ReportDS is the name of the connection which we had created on Step 2.

    Implementing Data Security In Canned Reports Based On Logged In User Name

    Once we select the Groovy connection, the SQL type changes to Groovy. Now write the code below in the Groovy SQL placeholder.

    Implementing Data Security In Canned Reports Based On Logged In User Name

    import com.helicalinsight.efw.utility.GroovyUsersSession
    public String evalCondition() {
    
        String userName = GroovyUsersSession.getValue('${user}.name')
        userName = userName.replaceAll("'", "")
    
        String responseJson
        String selectClause = '''SELECT * FROM "employee_details"'''
        String whereClause = """ WHERE "employee_name"='${userName}'"""
    
        if (!userName.equals("hiadmin")) {
            responseJson = selectClause + whereClause
        } else {
            responseJson = selectClause;
        }
    
        return responseJson
    }
    

    Code Explanation: We are fetching the name of the user and storing it in a variable. There is a base query. If the user name is hiadmin, only the base query runs with full data. Whereas if the username is anything except hiadmin, then a whereclause also gets added and restricting the user to see only the data based on his user name.

    After entering the Groovy SQL, click Save and then Run. This will return the query response. This Groovy code is very similar to Java. More and more complex conditions can also be put which can check multiple conditions and values like user name, organization name, role, profiles etc.

  6. Now go to the Canvas, create the required canned report, and then save it.

  7. Implementing Data Security In Canned Reports Based On Logged In User Name

  8. We have saved the report and the Groovy connection (created on step 2) in the same folder which makes it easy to share.

  9. Implementing Data Security In Canned Reports Based On Logged In User Name

  10. Now share the data source connection, Groovy Managed Connection, and report folder with the user you want to provide access to, with appropriate permissions. In this example, we shared them with the user name “Mitchell Harper”. To read more about sharing you can read here
    https://www.helicalinsight.com/sharing-reports/

    If you have saved the Groovy Connection in a different folder, please make sure that you share all the respective resources and folders properly.

  11. Implementing Data Security In Canned Reports Based On Logged In User Name

    Implementing Data Security In Canned Reports Based On Logged In User Name

    Implementing Data Security In Canned Reports Based On Logged In User Name

Report view test case 1 :

Report view when we logged in with USER : hiadmin

Note: This user can view all the employees data.

Implementing Data Security In Canned Reports Based On Logged In User Name

Report view test case 2 :

We created a user Mitchell Harper

Report view when we logged in with USER : Mitchell Harper

Note: This user can view only the entries with employee as Mitchell Harper, according to the condition specified in the SQL query for the report.

Implementing Data Security In Canned Reports Based On Logged In User Name

Please reach out to support@helicalinsight.com in case of any more questions.

Leave a Reply

Helical Insight’s self-service capabilities is one to reckon with. It allows you to simply drag and drop columns, add filters, apply aggregate functions if required, and create reports and dashboards on the fly. For advanced users, the self-service component has ability to add javascript, HTML, HTML5, CSS, CSS3 and AJAX. These customizations allow you to create dynamic reports and dashboards. You can also add new charts inside the self-service component, add new kind of aggregate functions and customize it using our APIs.
Helical Insight’s self-service capabilities is one to reckon with. It allows you to simply drag and drop columns, add filters, apply aggregate functions if required, and create reports and dashboards on the fly. For advanced users, the self-service component has ability to add javascript, HTML, HTML5, CSS, CSS3 and AJAX. These customizations allow you to create dynamic reports and dashboards. You can also add new charts inside the self-service component, add new kind of aggregate functions and customize it using our APIs.
Helical Insight, via simple browser based interface of Canned Reporting module, also allows to create pixel perfect printer friendly document kind of reports also like Invoice, P&L Statement, Balance sheet etc.
Helical Insight, via simple browser based interface of Canned Reporting module, also allows to create pixel perfect printer friendly document kind of reports also like Invoice, P&L Statement, Balance sheet etc.
If you have a product, built on any platform like Dot Net or Java or PHP or Ruby, you can easily embed Helical Insight within it using iFrames or webservices, for quick value add through instant visualization of data.
If you have a product, built on any platform like Dot Net or Java or PHP or Ruby, you can easily embed Helical Insight within it using iFrames or webservices, for quick value add through instant visualization of data.
Being a 100% browser-based BI tool, you can connect with your database and analyse across any location and device. There is no need to download or install heavy memory-consuming developer tools – All you need is a Browser application! We are battle-tested on most of the commonly used browsers.
Being a 100% browser-based BI tool, you can connect with your database and analyse across any location and device. There is no need to download or install heavy memory-consuming developer tools – All you need is a Browser application! We are battle-tested on most of the commonly used browsers.
We have organization level security where the Superadmin can create, delete and modify roles. Dashboards and reports can be added to that organization. This ensures multitenancy.
We have organization level security where the Superadmin can create, delete and modify roles. Dashboards and reports can be added to that organization. This ensures multitenancy.
We have organization level security where the Superadmin can create, delete and modify roles. Dashboards and reports can be added to that organization. This ensures multitenancy.
We have organization level security where the Superadmin can create, delete and modify roles. Dashboards and reports can be added to that organization. This ensures multitenancy.
A first-of-its-kind Open-Source BI framework, Helical Insight is completely API-driven. This allows you to add functionalities, including but not limited to adding a new exporting type, new datasource type, core functionality expansion, new charting in adhoc etc., at any place whenever you wish, using your own in-house developers.
A first-of-its-kind Open-Source BI framework, Helical Insight is completely API-driven. This allows you to add functionalities, including but not limited to adding a new exporting type, new datasource type, core functionality expansion, new charting in adhoc etc., at any place whenever you wish, using your own in-house developers.
It handles huge volumes of data effectively. Caching, Pagination, Load-Balancing and In-Memory not only provides you with amazing experience, but also and does not burden the database server more than required. Further effective use of computing power gives best performance and complex calculations even on the big data even with smaller machines for your personal use. Filtering, Sorting, Cube Analysis, Inter Panel Communication on the dashboards all at lightning speed. Thereby, making best open-source Business Intelligence solution in the market.
It handles huge volumes of data effectively. Caching, Pagination, Load-Balancing and In-Memory not only provides you with amazing experience, but also and does not burden the database server more than required. Further effective use of computing power gives best performance and complex calculations even on the big data even with smaller machines for your personal use. Filtering, Sorting, Cube Analysis, Inter Panel Communication on the dashboards all at lightning speed. Thereby, making best open-source Business Intelligence solution in the market.
With advance NLP algorithm, business users simply ask questions like, “show me sales of last quarter”, “average monthly sales of my products”. Let the application give the power to users without knowledge of query language or underlying data architecture
With advance NLP algorithm, business users simply ask questions like, “show me sales of last quarter”, “average monthly sales of my products”. Let the application give the power to users without knowledge of query language or underlying data architecture
Our application is compatible with almost all databases, be it RDBMS, or columnar database, or even flat files like spreadsheets or csv files. You can even connect to your own custom database via JDBC connection. Further, our database connection can be switched dynamically based on logged in users or its organization or other parameters. So, all your clients can use the same reports and dashboards without worrying about any data security breech.
Our application is compatible with almost all databases, be it RDBMS, or columnar database, or even flat files like spreadsheets or csv files. You can even connect to your own custom database via JDBC connection. Further, our database connection can be switched dynamically based on logged in users or its organization or other parameters. So, all your clients can use the same reports and dashboards without worrying about any data security breech.
Our application can be installed on an in-house server where you have full control of your data and its security. Or on cloud where it is accessible to larger audience without overheads and maintenance of the servers. One solution that works for all.
Our application can be installed on an in-house server where you have full control of your data and its security. Or on cloud where it is accessible to larger audience without overheads and maintenance of the servers. One solution that works for all.
Different companies have different business processes that the existing BI tools do not encompass. Helical Insight permits you to design your own workflows and specify what functional module of BI gets triggered
Different companies have different business processes that the existing BI tools do not encompass. Helical Insight permits you to design your own workflows and specify what functional module of BI gets triggered