<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic QlikSense Security Rules in App Development</title>
    <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073943#M17645</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, i need to know the logic of the evaluation of the security rules in qmc&lt;/P&gt;&lt;P&gt;In this case are them evaluated in '&lt;EM&gt;and&lt;/EM&gt;' condition or in '&lt;EM&gt;or&lt;/EM&gt;' condition?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="sec_rules.png" class="jive-image image-1" src="https://community.qlik.com/legacyfs/online/116665_sec_rules.png" style="height: 193px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2016 16:31:32 GMT</pubDate>
    <dc:creator>marco_puccetti</dc:creator>
    <dc:date>2016-03-02T16:31:32Z</dc:date>
    <item>
      <title>QlikSense Security Rules</title>
      <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073943#M17645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, i need to know the logic of the evaluation of the security rules in qmc&lt;/P&gt;&lt;P&gt;In this case are them evaluated in '&lt;EM&gt;and&lt;/EM&gt;' condition or in '&lt;EM&gt;or&lt;/EM&gt;' condition?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="sec_rules.png" class="jive-image image-1" src="https://community.qlik.com/legacyfs/online/116665_sec_rules.png" style="height: 193px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2016 16:31:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073943#M17645</guid>
      <dc:creator>marco_puccetti</dc:creator>
      <dc:date>2016-03-02T16:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense Security Rules</title>
      <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073944#M17646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A user begins with no access at all. You can only add permissions, not remove them. So any rule that gives a user permission to do something with an object will result in that user having that permission. Other rules cannot undo this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2016 12:59:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073944#M17646</guid>
      <dc:creator>Gysbert_Wassenaar</dc:creator>
      <dc:date>2016-03-03T12:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense Security Rules</title>
      <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073945#M17647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case how are applied the streams within a rule?&lt;/P&gt;&lt;P&gt;When there are two roles&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;ContentAdmin&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;SecurityAdmin&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;RootAdmin&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;In "and" or in "or" logic condition&lt;/STRONG&gt;&lt;/SPAN&gt;? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="content_admin.png" class="jive-image image-2" src="https://community.qlik.com/legacyfs/online/116803_content_admin.png" style="height: 497px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="security_admin.png" class="jive-image image-3" src="https://community.qlik.com/legacyfs/online/116810_security_admin.png" style="height: 503px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="root_admin.png" class="image-4 jive-image" src="https://community.qlik.com/legacyfs/online/116811_root_admin.png" style="height: 497px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with different types of authorization, which of them are applied or they are applied both at the same time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is the following: i have a mashup application (extension) that is configured to be accessible locally, but from external machine (even if the access is set to anonymous) i get this error (the local user has the role of &lt;STRONG&gt;RootAdmin&lt;/STRONG&gt; and it's also configured in the securityu rules):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NoAvailableAccess.png" class="jive-image image-1" src="https://community.qlik.com/legacyfs/online/116801_NoAvailableAccess.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;So i have considered the error due to a bad server configuration. Have i to change the Resource filter too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2016 14:07:46 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073945#M17647</guid>
      <dc:creator>marco_puccetti</dc:creator>
      <dc:date>2016-03-03T14:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense Security Rules</title>
      <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073946#M17648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marco - let me put another set of eyes on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.qlik.com/qlik-users/4919"&gt;jog&lt;/A&gt;‌ - anything you want to add?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark the appropriate replies as CORRECT / HELPFUL so our team and other members know that your question(s) has been answered to your satisfaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mike Tarallo&lt;/P&gt;&lt;P&gt;Qlik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2016 15:39:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073946#M17648</guid>
      <dc:creator>Michael_Tarallo</dc:creator>
      <dc:date>2016-03-03T15:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense Security Rules</title>
      <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073947#M17649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No available access type means they don't have a token allocated to them to access.&amp;nbsp; This is a license access rule issue and not a security rule issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;License rules are evaluated first to authenticate you to Qlik Sense (that is allocate a token).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security rules are evaluated second to authorize your capabilities and access to Qlik Sense resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Gysbert said, all security rules are additive.&amp;nbsp; They will run in whatever order they run, but the most privilege rule will win out.&amp;nbsp; Moreover, security rules are constantly re-evaluated against the user in the event their access changes during a session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2016 16:22:11 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073947#M17649</guid>
      <dc:creator />
      <dc:date>2016-03-03T16:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: QlikSense Security Rules</title>
      <link>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073948#M17650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried to configure a login access rule but it doesn't work properly:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="licence_access_rules.png" class="jive-image image-1" src="https://community.qlik.com/legacyfs/online/116855_licence_access_rules.png" style="height: 425px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What have i to change in order to give the access to the extensions objects, to any machine in the net without any kind of credential?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2016 16:54:33 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/QlikSense-Security-Rules/m-p/1073948#M17650</guid>
      <dc:creator>marco_puccetti</dc:creator>
      <dc:date>2016-03-03T16:54:33Z</dc:date>
    </item>
  </channel>
</rss>

