Forum Discussion

IoanaSluby's avatar
IoanaSluby
Frequent Visitor
6 years ago
Solved

Configure Row Level Security with OR condition

Hi!

 

I have a main datasource which contains data about worklogs, grouped by month/year/project and employee, with these fields:

- Employee

- Project

- Month 

- Year

- Time in hours 

- Employee division

- Project Division

And one RLS tables with these fields:

- division (which can be either employee division or project division)

- User (email address)

 

The role that i created is based on the rule that User = USERPRINCIPALNAME()

 

How could I simulate an or condition so that for a specific user data could be displayed either when employee division = division from RLS or project division = division from RLS?

 

The relation between tables is many to many, a user can be assigned to multiple divisions.

 

  • Anonymous's avatar
    Anonymous
    6 years ago

    Hi,

     

    You can apply RLS to the main table (WorkLogs) instead of the RLS table and check like this:

    = CONTAINS('RLSTable', 'RLSTable'[User], USERPRINCIPALNAME(), 'RLSTable'[division], 'WorkLogs'[Employee division])

    || CONTAINS('RLSTable', 'RLSTable'[User], USERPRINCIPALNAME(), 'RLSTable'[division], 'WorkLogs'[Project division])

     

    You don't need any relations between the two tables. Caching of RLS will stop working if you have more than about 130 000 rows, but if the table is not too big it will probably work even if you exceed that number.

     

    If performance is not good enough with the above solution, my suggestion is to add some kind of bridge table between the WorkLogs table and RLStable that connects worklog rows with rows in the RLS table.

     

    Best Regards // Ulf

8 Replies

  • Anonymous's avatar
    Anonymous
    Not applicable

    Hi,

     

    You can apply RLS to the main table (WorkLogs) instead of the RLS table and check like this:

    = CONTAINS('RLSTable', 'RLSTable'[User], USERPRINCIPALNAME(), 'RLSTable'[division], 'WorkLogs'[Employee division])

    || CONTAINS('RLSTable', 'RLSTable'[User], USERPRINCIPALNAME(), 'RLSTable'[division], 'WorkLogs'[Project division])

     

    You don't need any relations between the two tables. Caching of RLS will stop working if you have more than about 130 000 rows, but if the table is not too big it will probably work even if you exceed that number.

     

    If performance is not good enough with the above solution, my suggestion is to add some kind of bridge table between the WorkLogs table and RLStable that connects worklog rows with rows in the RLS table.

     

    Best Regards // Ulf

    • IoanaSluby's avatar
      IoanaSluby
      Frequent Visitor

      I think because of the relation (many to many) it gives me an error: A single value value for column Employee division cannot be determined. This can happen when a measure refers to column that contains many values without specifying an aggregation.

       

       

  • sturlaws's avatar
    sturlaws
    Resident Rockstar

    Hi IoanaSluby 

     

    how to do this will depend on your data and the desired output. Could you provide some relevant sample data and a mockup of your desired output?

     

    Cheers,
    Sturla

     

     

    • IoanaSluby's avatar
      IoanaSluby
      Frequent Visitor

      Currently, there is a relation between the RLS table and Project Division (RLS filtering Main datasource) and a role which says that User = USERPRINCIPALNAME().

      What i would like to achieve is displaying for User = [email protected], since he has rights on Commerce division, both the rows where Employee Division = Commerce or where Project Division = Commerce.

      • Anonymous's avatar
        Anonymous
        Not applicable

        IoanaSlubyDid you get the error message when you tried the DAX I posted earlier? It should be on the main data source table, not on the RLS table. And you should remove the relationship.

         

        RLS expression on Main Data source table:

        = CONTAINS('RLS Table', 'RLS Table'[User], USERPRINCIPALNAME(), 'RLS Table'[Division], 'Main Data source'[Employee division])

        || CONTAINS('RLS Table', 'RLS Table'[User], USERPRINCIPALNAME(), 'RLS Table'[Division], 'Main Data source'[Project division])

         

        Best Regards // Ulf