Forum Discussion
RLS and App
- 1 year ago
Hi Peter_23
It’s important to understand that there is no direct link between RLS (Row-Level Security) and App Audience settings because one controls row filtering, while the other determines which reports or pages are visible in the app.
RLS is designed to filter data based on user permissions, meaning users will only see the rows they are authorized to view within the report. On the other hand, App Audience settings control which reports or pages users can access in the app.
Both mechanisms operate independently:
- RLS filters the content within the report based on permissions.
- App Audience manages access to specific reports or pages within the app.
To ensure everything is working as expected, here are the checks you should perform:
-
Workspace Access: If the test group has access to the workspace, they will be able to see all reports, regardless of the app audience settings. Make sure the test group does not have direct workspace access, and only access the reports through the app.
-
App Audience Settings: Ensure that the test group is correctly configured in the audience that can only see the "Country" report and not the "State" report. Audiences must be accurately defined to prevent access to restricted content.
-
RLS Validation: Verify that RLS is properly configured on both reports, and that the test group is filtered correctly for each report so that users only see the data they are permitted to view.
If this post helps, then please consider Accepting it as the solution to help the other members find it more quickly
Hi Peter_23
There is no connection between RLS and the app audience.
The app audience defines who can see the report or a section of the report.
RLS (Row-Level Security) is used to filter rows.
These are two completely separate settings that do not affect each other.
If this post helps, then please consider Accepting it as the solution to help the other members find it more quickly
Thanks Ritaf1983 when you publish the app. is it available to anybody in organization or only to audiences? If it's to anybody, is there a posibility to restrict to audiences?
- Ritaf19831 year agoSuper User
Hi Peter_23
Only to audiences.If this post helps, then please consider Accepting it as the solution to help the other members find it more quickly
- Peter_231 year agoAdvocate V
Ritaf1983 I have a update topic, so my configuration is: test user -> test group . I created: one report for "state" and another for "country" inside the app the restriction is "state" NOT viewing to "test group". "Country" is allow to "test group". Same workspace.
RLS is activate with "test group" to filter rows allowed. (both reports, same configuration)
IF I do testing with RLS in any reports with test group and viewer role in workspace. It's works fine.
IF I do testing with only APP with test group. It allow to view "Country" report. It's fine.
And finally
Test One:
with APP and RLS together with same test group. The audiencies do not working, show me all reports, but the RLS is working! 😞 I figure out because the group have access to workspace.
Test two
Remove access to test group in workspace, but I didn't access to APP, thorugh the share link show me: "Let's get your permission to view this app" ...
Is there a missing option configuration to works together (APP and RLS)? eg. "Allow people to share the datasets in this app audienced".. "allow people to build content.."
Or do am I have two separe groups: one for audiences and one for RLS?
thanks in advance.
- Ritaf19831 year agoSuper User
Hi Peter_23
It’s important to understand that there is no direct link between RLS (Row-Level Security) and App Audience settings because one controls row filtering, while the other determines which reports or pages are visible in the app.
RLS is designed to filter data based on user permissions, meaning users will only see the rows they are authorized to view within the report. On the other hand, App Audience settings control which reports or pages users can access in the app.
Both mechanisms operate independently:
- RLS filters the content within the report based on permissions.
- App Audience manages access to specific reports or pages within the app.
To ensure everything is working as expected, here are the checks you should perform:
-
Workspace Access: If the test group has access to the workspace, they will be able to see all reports, regardless of the app audience settings. Make sure the test group does not have direct workspace access, and only access the reports through the app.
-
App Audience Settings: Ensure that the test group is correctly configured in the audience that can only see the "Country" report and not the "State" report. Audiences must be accurately defined to prevent access to restricted content.
-
RLS Validation: Verify that RLS is properly configured on both reports, and that the test group is filtered correctly for each report so that users only see the data they are permitted to view.
If this post helps, then please consider Accepting it as the solution to help the other members find it more quickly