13 views

 

Issue Description


Users with access to reports and/or widgets on a dashboard can view the counts for data that they would not normally have access to due to ACL restrictions on the source table.

Symptoms


A user viewing a dashboard containing reports or widgets for a table they are restricted from viewing by ACLs can still see the data on the report/widget. however, when they click through to the list no data will be returned.

Release


All versions

Cause


Reports and widgets do not evaluate ACLs when processing data to be displayed.

When you click through to the list, the data is not displayed as expected, due to the ACLs being evaluated for each record displayed.

Resolution


This is the expected behaviour and no workaround is available.

Possible options for mitigating access to the data is to:

  1. Ensure that the dashboards shared with a user contain only data they can also access.
  2. Use a Before Query Business Rule to restrict access to data if possible instead of the ACL.

Article Information

Last Updated:2018-04-23 02:27:39
Published:2018-04-23