Skip to content

How to filter data in a view according to connected user###

The feature is implemented by the DefaultFilter node at model or view level.

For example, suppose that in your config.yaml file the login ReadUserCommandText is implemented as in the following:

yaml
.....
  ReadUserCommandText: |
    select
      A.ID AS USER_NAME, a.PASSWD AS PASSWORD_HASH, 
      a.SYSYEM as SYSTEM, E.ID AS EMPLOYEEID, E.DX AS EMPLOYEEDX
      from APPUSER A 
      LEFT JOIN employee E ON E.APPUSERCLASS = 'TISUser' AND E.APPUSERID = A.ID

Suppose in a model or view you want to show only records of current user.

just write in the model or in the view the following code (implemented for a view):

yaml
.....
MainTable:
.....
  DefaultFilter: |
    (EMPLOYEEID in (select ID FROM EMPLOYEE where APPUSERID = '%Auth:USER_NAME%'))

where %Auth:USER_NAME% is a macro expanded by Kittox

a more complex example: you want to show all records in case current user is a system user. Just use the %Auth:SYSTEM% macro as in the following:

yaml
.....
MainTable:
.....
  DefaultFilter: |
 ('%Auth:SYSTEM%' = 1 or 
  (EMPLOYEEID in (select ID FROM EMPLOYEE where APPUSERID = '%Auth:USER_NAME%')))

DefaultFilter vs Controller/FilterExpression

Both restrict the records a view works on, but only one of them is a guarantee:

NodeApplies to
DefaultFilter (model or view table)every load of that table — grid, form, lookup, export, detail table, and the key-based endpoints. It is part of the where clause the SQL builder produces
Controller/FilterExpressionthe record a standalone form loads, plus the key-based endpoints of that view

So when the point is isolation — this user may only ever see their own rows — put the predicate in DefaultFilter, at model level if it must hold for every view of that model. Use FilterExpression to pick the single record of a standalone form.

FilterExpression covers the key-based endpoints

FilterExpression is combined with the view filter on the key-based endpoints (kx/view/<V>/form, /save, /delete, /blob) as well as on the standalone-form load, so a request that supplies a record key cannot bypass it and be answered from the whole table. DefaultFilter is applied on every load regardless.

Released under Apache License, Version 2.0.