<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Rule to Access an App without having access to the Stream in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17057#M285</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one thing you can try instead of complex security rules, is create a separate stream for mashup applications and give access to only mashup users and restrict for all users.&lt;/P&gt;&lt;P&gt;This will make your life easy, as it wont need much maintenance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kaushik Solanki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Feb 2018 10:05:39 GMT</pubDate>
    <dc:creator>kaushiknsolanki</dc:creator>
    <dc:date>2018-02-27T10:05:39Z</dc:date>
    <item>
      <title>Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17056#M284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to give permisson to user to&amp;nbsp; specific apps without give them access to the stream where the apps are published. Why do I try such a "strange" thing? In this special case i'll created a mashup for those apps, therefore i only want to grant the user to the mashup and the should not be able to see the corresponding app in the hub (That's why I'm trying to hide the stream where the app is published)).&lt;/P&gt;&lt;P&gt;Therefore my question is it possible to give user directly access to&amp;nbsp; an app without having access to the Stream? Or is there any other way how I can hide the stream to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My setup is the QS Server November Relase.&lt;/P&gt;&lt;P&gt;We had setup up an access concept on stream and on app layer by custom properties. Similar to this video (&lt;A href="https://www.youtube.com/watch?v=feSaaJZ7Jco" title="https://www.youtube.com/watch?v=feSaaJZ7Jco"&gt;Qlik Sense Stream Management Security Rules and Exception Management - YouTube&lt;/A&gt;) .&lt;/P&gt;&lt;P&gt;We have created two different Streams, Apps (Where the normal apps are stored), Mashup (The stream where all apps which are used only for mashup are stored into and that stream which should be hidden)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help,&lt;/P&gt;&lt;P&gt;Best regards Oli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 09:59:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17056#M284</guid>
      <dc:creator>hartmoli</dc:creator>
      <dc:date>2018-02-27T09:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17057#M285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one thing you can try instead of complex security rules, is create a separate stream for mashup applications and give access to only mashup users and restrict for all users.&lt;/P&gt;&lt;P&gt;This will make your life easy, as it wont need much maintenance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kaushik Solanki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 10:05:39 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17057#M285</guid>
      <dc:creator>kaushiknsolanki</dc:creator>
      <dc:date>2018-02-27T10:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17058#M286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you already have a Stream dedicated to Mashup's, why do you want to hide that Stream ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 10:14:18 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17058#M286</guid>
      <dc:creator>YoussefBelloum</dc:creator>
      <dc:date>2018-02-27T10:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17059#M287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="color: #3d3d3d; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Kaushik,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Thank you for your reply. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;Thats what I've already tried. But it doesn't match my requirements. Cause if i handle this like your proposal, the mashup user can still go to the hub and see the stream and thus the app. And my requirements are: The mashup user only should have access to the mashup and should not be able to see the mashup stream, so that he doesnt have the opportunity to go the app via the qlik hub. Or do I missunderstand your proposal?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 10:14:25 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17059#M287</guid>
      <dc:creator>hartmoli</dc:creator>
      <dc:date>2018-02-27T10:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17060#M288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cause the only point how the user should access the information is via the mashup. He should not be able to access the app via the hub. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 10:16:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17060#M288</guid>
      <dc:creator>hartmoli</dc:creator>
      <dc:date>2018-02-27T10:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17061#M289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.qlik.com/thread/240954" title="https://community.qlik.com/thread/240954"&gt;https://community.qlik.com/thread/240954&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps to understand and solve your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kaushik Solanki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 10:24:00 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17061#M289</guid>
      <dc:creator>kaushiknsolanki</dc:creator>
      <dc:date>2018-02-27T10:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17062#M290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the link.&lt;/P&gt;&lt;P&gt;I've already came to this community entry due to my research, but as i do understand this, it only restrict the access to the personal section in the hub and not to certain streams. &lt;/P&gt;&lt;P&gt;Regarding to this video: &lt;A href="https://help.qlik.com/en-US/sense/3.1/Content/Videos/Videos-disable-hub.htm?_ga=2.205245776.1145152359.1519629556-797353991.1514377215" title="https://help.qlik.com/en-US/sense/3.1/Content/Videos/Videos-disable-hub.htm?_ga=2.205245776.1145152359.1519629556-797353991.1514377215"&gt;https://help.qlik.com/en-US/sense/3.1/Content/Videos/Videos-disable-hub.htm?_ga=2.205245776.1145152359.1519629556-797353…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 10:31:48 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17062#M290</guid>
      <dc:creator>hartmoli</dc:creator>
      <dc:date>2018-02-27T10:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17063#M291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the outset, Security rules are applied equally on the Hub as they are on Mashups. If you want to &lt;EM&gt;prevent&lt;/EM&gt; visibility on the Hub but allow access via the mashup, then this is not going to be possible in any realistic scenario assuming all things are equal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you &lt;EM&gt;can&lt;/EM&gt; do, is as follows:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Disable the Stream security rule which inherits rights from the Stream &amp;gt; App &amp;gt; App.Object&lt;/LI&gt;&lt;LI&gt;Recreate a new rule which breaks this inheritance for a single stream&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What this will do is mean that the user will not see the Stream which makes it difficult to access the app, but they could, in theory, access the App via &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://sense.company.com/sense/app/AppGUID" rel="nofollow" target="_blank"&gt;https://sense.company.com/sense/app/AppGUID&lt;/A&gt;&lt;SPAN&gt;. Basically they can see the app but can't see the stream.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Name: _StreamMashupUseCase&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Description: This will allow inheritance for all streams except the stream named mashup&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Filter: App*&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Actions: Read / Publish&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Conditions: (resource.resourcetype = "App" and resource.stream.HasPrivilege("read") and resource.stream.name !="mashup") or ((resource.resourcetype = "App.Object" and resource.published ="true" and resource.objectType != "app_appscript" and resource.objectType != "loadmodel") and resource.app.stream.HasPrivilege("read"))&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Context: Hub and QMC&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Name: _StreamMashup-AppLevel&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Description: This will grant read rights to a specified App GUID + the App Objects based on a user criterion&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Filter: App*&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Actions: Read / Publish&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Conditions: (resource.resourcetype = "App" and resource.id="dea8864b-734c-42c3-b8c1-2d789409a817") or (resource.resourcetype = "App.Object" and resource.published ="true" and resource.objectType != "app_appscript" and resource.objectType != "loadmodel")&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;and user.userId="mashupexclusion"&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Context: Hub and QMC&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 19:24:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17063#M291</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2018-02-27T19:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17064#M292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Levi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you a lot for your comprehensive answer. &lt;/P&gt;&lt;P&gt;It's exactly what I was looking for. I'm aware of the fact that the access to the app via APP-ID will still be possible, but I dont see this as a big problem. For me its important that the app is not easily accessible via the hub.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wasnt aware of the concept of inheritance, thank you for open my eyes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I diasbled the default Stream Rule and implemented your proposed two rules. Now I can access the app and the mashup. But unfortunately, something is still blocking the access to the app objects. By accessing the App directly via ID, I can see an app without any sheets. I guess I need to disable still one rule or I have to give somewhere more rights, do you have an Idea where this issue could be caused?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, thank you a lot for your help, its a big step forward.&lt;SPAN style="font-size: 10pt;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 09:15:07 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17064#M292</guid>
      <dc:creator>hartmoli</dc:creator>
      <dc:date>2018-02-28T09:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17065#M293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Levi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New knowledge..&lt;/P&gt;&lt;P&gt;It works as you proposed. I tried to generalize the user access by "((user.@group)=resource.@group))", what doesnt work in this way. I guess the proplem is located by how we've choosen the approach to give permisson to a stream and app, we do that by the group attribute and give permisson to the app also by the group attribute. In this special case I only allocated this attribute only to the app, thus I dont want that the user can see the stream. I think the problem is located there that the expression&amp;nbsp; "((user.@group)=resource.@group))" doesnt work, cause I think by resource is the stream and app intended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 10:43:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17065#M293</guid>
      <dc:creator>hartmoli</dc:creator>
      <dc:date>2018-02-28T10:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17066#M294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh. Thanks for the update. I'm glad to hear things are working as expected at this point.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 13:20:21 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/17066#M294</guid>
      <dc:creator>Levi_Turner</dc:creator>
      <dc:date>2018-02-28T13:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Security Rule to Access an App without having access to the Stream</title>
      <link>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/1578263#M13524</link>
      <description>&lt;P&gt;Hi Hartmoli,&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you manage to solve the problem with the missing sheets? I am facing the same issue and would appreciate your help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rujena&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 08:26:59 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Security-Rule-to-Access-an-App-without-having-access-to-the/m-p/1578263#M13524</guid>
      <dc:creator>Rujena</dc:creator>
      <dc:date>2019-05-09T08:26:59Z</dc:date>
    </item>
  </channel>
</rss>

