Forum Discussion
"shouldn't have effective identity" error when passing identity to embedded report with no RLS
The report without RLS defined should use the the identity withour the Effective identity.
generateTokenRequestParameters = new GenerateTokenRequest(accessLevel: "view");
The Sample implement the following:
GenerateTokenRequest generateTokenRequestParameters;
// This is how you create embed token with effective identities
if (!string.IsNullOrEmpty(username))
{
var rls = new EffectiveIdentity(username, new List<string> { report.DatasetId });
if (!string.IsNullOrWhiteSpace(roles))
{
var rolesList = new List<string>();
rolesList.AddRange(roles.Split(','));
rls.Roles = rolesList;
}
// Generate Embed Token with effective identities.
generateTokenRequestParameters = new GenerateTokenRequest(accessLevel: "view", identities: new List<EffectiveIdentity> { rls });
}
else
{
// Generate Embed Token for reports without effective identities.
generateTokenRequestParameters = new GenerateTokenRequest(accessLevel: "view");
}The UI has string defined with two Input Boxes, which is used to identify whether it need to generate the Effective Identity.
Which I think you may take a try with a similar way.
Regards,
Michael
I see, but this only works if there is no login session at all. What we have is a situation where all employees of a company login into the web application that has Power Bi embedded. There are a certain set of reports that do not have RLS and are available to everyone in the company, yet they still have an Azure AD login session with PrincipalCase including email adresses and such.
All users would have a username which we would be using the Azure AD Email address, they are defaulted to a generic role of "employee" so there is no case where their username is null or empty, so we end up passing all the identity information to all reports regardless of the report implementing RLS.
The reports with RLS will embed successfully, but reports that have no RLS will fail to embed since we are passing it identity information that it doesn't need.
- davidjrh6 years agoNew Member
This is still an issue almost two years later. Should I just catch the exception and then retry with passing no RLS? That sounds like a bad implementation to me.