<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to interpret SharedContent security rule? in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835394#M31010</link>
    <description>&lt;P&gt;Hi, I haven't tested but I think this rule gives permission to publish links in qlik sense, this should be the service account of qlikView, the users who an actually see the document are set in QlikView Management Console.&lt;/P&gt;&lt;P&gt;I would try to give only permission to the srevice accounts, set the QV task to publish to a named user that is not an admin user, and check if the user sees the documento.&lt;/P&gt;&lt;P&gt;I don't have now an environment avaible to test myself.&lt;/P&gt;</description>
    <pubDate>Sun, 12 Sep 2021 07:27:57 GMT</pubDate>
    <dc:creator>rubenmarin</dc:creator>
    <dc:date>2021-09-12T07:27:57Z</dc:date>
    <item>
      <title>How to interpret SharedContent security rule?</title>
      <link>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835280#M31007</link>
      <description>&lt;P&gt;Qlik has &lt;A href="https://help.qlik.com/en-US/qlikview/May2021/Subsystems/QMC/Content/QV_QMC/QMC_Documents_SourceDocuments_Distribute_QlikSense_SharedContent.htm" target="_blank" rel="noopener"&gt;this documentation&lt;/A&gt;&amp;nbsp;on topic of publishing QlikView app links to Qlik Sense hub. Title of the doc, "...&lt;STRONG&gt;allow users to publish a link to shared content&lt;/STRONG&gt;", is a bit scary.&lt;/P&gt;&lt;P&gt;I don't want any user in the entire company directory to be able to publish links. I want &lt;STRONG&gt;specific service account&lt;/STRONG&gt; that runs QlikView server to be able to publish links to QlikView documents section in the hub.&lt;/P&gt;&lt;P&gt;My question is, am I reading the rule correctly? Is the rule that's mentioned &lt;A href="https://help.qlik.com/en-US/qlikview/May2021/Subsystems/QMC/Content/QV_QMC/QMC_Documents_SourceDocuments_Distribute_QlikSense_SharedContent.htm" target="_blank" rel="noopener"&gt;the doc&lt;/A&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Allows &lt;STRONG&gt;any user&lt;/STRONG&gt; to somehow publish links to &lt;STRONG&gt;QlikView documents&lt;/STRONG&gt; section in Qlik Sense hub OR&lt;/LI&gt;&lt;LI&gt;Allows QlikView service account to publish links to QlikView apps in &lt;STRONG&gt;QlikView documents&lt;/STRONG&gt; section &lt;STRONG&gt;for any user&lt;/STRONG&gt;?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mikhail B.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:57:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835280#M31007</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2025-01-29T16:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to interpret SharedContent security rule?</title>
      <link>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835323#M31008</link>
      <description>&lt;P&gt;Hi, the rule you have linked will only give permissions to users that belong to the group specified in UserGroupName.&lt;/P&gt;&lt;P&gt;You can also set this for specific users using UserId or UserName instead of UserDirectory.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another usual option is to use UserRole to give this permissions to users with specific roles on qlikSense, like the RootAdmin or the ContentAdmin.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 08:07:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835323#M31008</guid>
      <dc:creator>rubenmarin</dc:creator>
      <dc:date>2021-09-11T08:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to interpret SharedContent security rule?</title>
      <link>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835360#M31009</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/22593"&gt;@rubenmarin&lt;/a&gt;&amp;nbsp;, thanks for the reply! I understand who the rule applies to. I’m more curious about what these users will now be able to do when they have this permission.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 14:19:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835360#M31009</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2021-09-11T14:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to interpret SharedContent security rule?</title>
      <link>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835394#M31010</link>
      <description>&lt;P&gt;Hi, I haven't tested but I think this rule gives permission to publish links in qlik sense, this should be the service account of qlikView, the users who an actually see the document are set in QlikView Management Console.&lt;/P&gt;&lt;P&gt;I would try to give only permission to the srevice accounts, set the QV task to publish to a named user that is not an admin user, and check if the user sees the documento.&lt;/P&gt;&lt;P&gt;I don't have now an environment avaible to test myself.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Sep 2021 07:27:57 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835394#M31010</guid>
      <dc:creator>rubenmarin</dc:creator>
      <dc:date>2021-09-12T07:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to interpret SharedContent security rule?</title>
      <link>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835791#M31011</link>
      <description>&lt;P&gt;&lt;FONT face="arial black,avant garde" size="5"&gt;&lt;STRONG&gt;THE ANSWER&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Figured it out. The answer is, this rule, just like &lt;A href="https://help.qlik.com/en-US/qlikview/May2021/Subsystems/QMC/Content/QV_QMC/QMC_Documents_SourceDocuments_Distribute_QlikSense_SharedContent.htm?_ga=2.20453243.297657245.1631540030-528109852.1631246341" target="_blank" rel="noopener"&gt;the document&lt;/A&gt; states,&amp;nbsp;&lt;EM&gt;"allow users to publish a link to shared content"&lt;/EM&gt;. In the context of publishing QlikView document links to Qlik Sense hub that means that the rule&amp;nbsp;&lt;STRONG&gt;allows any user to publish links to QlikView documents in Qlik Sense hub&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;I find title of the document so darn confusing without extra context behind it and the content of the document doesn't actually add any useful context that explains what&amp;nbsp;&lt;EM&gt;"allow users to publish a link to shared content"&lt;/EM&gt; actually means. For those interested in "the extra context", read on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial black,avant garde" size="5"&gt;ADDITIONAL CONTEXT&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Best way to start is to point out that Qlik Sense hub consists primarily of two sections:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Personal&lt;/LI&gt;&lt;LI&gt;Streams&lt;UL&gt;&lt;LI&gt;aka, public.&lt;/LI&gt;&lt;LI&gt;aka, not personal.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Notice that &lt;STRONG&gt;QlikView documents&lt;/STRONG&gt; section, counterintuitively, is located in &lt;STRONG&gt;Personal&lt;/STRONG&gt; space:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Location of QlikView documents section" style="width: 414px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/61831iDDAC47D721D254B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Qlik Sense Hub.png" alt="Location of QlikView documents section" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Location of QlikView documents section&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That implies that it works just like the &lt;STRONG&gt;Work&lt;/STRONG&gt; stream and it also further implies that:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Contents within &lt;STRONG&gt;QlikView documents&lt;/STRONG&gt; belong to specific user and &lt;STRONG&gt;only to that specific user&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Since contents within &lt;STRONG&gt;QlikView documents&lt;/STRONG&gt; belong to specific user, they &lt;STRONG&gt;can only be "created" by that specific user&lt;/STRONG&gt; in order to show up in that section for that user.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;So when QlikView distribution service publishes a link to QlikView documents section for a user, it actually creates a record in Qlik Sense repository database, specifically in SharedContent table of QSR database, and assigns user listed in distribution list in QlikView task as the "owner" of the link. That, in turn, makes the link to QlikView document show up for specific user.&lt;/P&gt;&lt;P&gt;If you'd like to confirm that, run this query in your Qlik Sense repository database to see list of QlikView links published to Qlik Sense hub and the "owners" of each link:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SELECT sc."ID"
	 , sc."Name"
	 , "Type"
	 , "Value"						as "AccessPointCategory"
	 , "Uri"
	 , "Owner_ID"
	 , "UserId"						as "Owner_Name"
	 , sc."CreatedDate"
	 , sc."ModifiedDate"
	 , sc."ModifiedByUserName"
  FROM public."SharedContents" sc
  LEFT JOIN public."SharedContentMetaDatas" scmd
    ON sc."ID" = scmd."SharedContent_ID"
  LEFT JOIN public."Users" u
    ON sc."Owner_ID" = u."ID"
 WHERE "Type" = 'QlikView doc link'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Notice that if app is distributed to, say, three users, there will be three records in that table for that app, one for each user and users are set as "owners" of the links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial black,avant garde" size="5"&gt;TESTING &amp;amp; CONFIRMATION&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I've done some testing and confirmation of how security rule works. First test was to setup security rule as described in &lt;A href="https://help.qlik.com/en-US/qlikview/May2021/Subsystems/QMC/Content/QV_QMC/QMC_Documents_SourceDocuments_Distribute_QlikSense_SharedContent.htm?_ga=2.20453243.297657245.1631540030-528109852.1631246341" target="_blank" rel="noopener"&gt;the document&lt;/A&gt; and distribute a QlikView app to Qlik Sense hub. That distribution was successful and user was able to see the link to the document in Qlik Sense hub.&lt;/P&gt;&lt;P&gt;Second test was to update the security rule to give Shared Content creation right only to the service account that's used to run QlikView:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Security rule modified to grant permission to service account" style="width: 846px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/61833i61E5B29B51B98393/image-size/large?v=v2&amp;amp;px=999" role="button" title="1. Security Rule - Permit Service Account.png" alt="Security rule modified to grant permission to service account" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Security rule modified to grant permission to service account&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I reran the distribution task in QV QMC, I got warning message saying that distribution to intended user ws forbidden:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Warning message issued in QlikView QMC when service account is the only account that has Create shared content permission" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/61834i63967541C89FB7C7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2. Security Rule - QV Service Account Only - 3 Users - 1st App.png" alt="Warning message issued in QlikView QMC when service account is the only account that has Create shared content permission" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Warning message issued in QlikView QMC when service account is the only account that has Create shared content permission&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That implied that user must have create shared content permission in Qlik Sense in order for a link to QlikView document to be distributed to that user's personal space in the hub.&lt;/P&gt;&lt;P&gt;However, implication is not quite the same as confirmation. So I took it a step further and modified the security rule to allow Create permission specifically for that user to which the QlikView app is being distributed:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Security rule modified to allow creation of shared content for specific user to whom QlikView document is being distributed" style="width: 844px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/61835i7823C13C006161FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="1. Security Rule - Permit Specific Users.png" alt="Security rule modified to allow creation of shared content for specific user to whom QlikView document is being distributed" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Security rule modified to allow creation of shared content for specific user to whom QlikView document is being distributed&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;The idea is if I reload the distribution task in QMC with this security rule modified to be focused specifically on the user that's on the distribution list in QV QMC, the link to the QlikView app should be created for the user without any errors or warnings. That, in fact is what happened. I reloaded the task in QMC with this new rule in place, it reloaded successfully, and the user confirmed the app did show up in their QlikView documents section in the hub.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 22:13:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/How-to-interpret-SharedContent-security-rule/m-p/1835791#M31011</guid>
      <dc:creator>mbespartochnyy</dc:creator>
      <dc:date>2021-09-13T22:13:49Z</dc:date>
    </item>
  </channel>
</rss>

