<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security issue in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619114#M1265114</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to set the restrictions in the document properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.png" class="jive-image" src="https://community.qlik.com/legacyfs/online/57104_1.png" style="width: 620px; height: 494px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Apr 2014 14:09:24 GMT</pubDate>
    <dc:creator>Bill_Britt</dc:creator>
    <dc:date>2014-04-11T14:09:24Z</dc:date>
    <item>
      <title>Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619105#M1265103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one app - with personell data - that is of course password-protected. There are two logon_tickets:&lt;/P&gt;&lt;P&gt;- One for myself and the developers (granting full access)&lt;/P&gt;&lt;P&gt;- One for the rest of the world (granting only viewing)&lt;/P&gt;&lt;P&gt;&amp;lt;=&amp;gt; This app (the figures contained in this app that is) are talked of every day at 8am in a special meeting that takes place every day.&lt;/P&gt;&lt;P&gt;=&amp;gt; The manager leading this meeting seemed to be not altogether happy with the fact that they have to enter a password, however&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; simple, to access that data.&lt;/P&gt;&lt;P&gt;&amp;lt;=&amp;gt; I won't sacrifize security altogether just for a little bit more comfort.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=&amp;gt; My question is: When the app for this meeting is opened, it contains a link opening the HR_app - could I pass the &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; logon_information in some form from this app to the HR_app so entering the username and password is not necessary? (there &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; would be no damage in that since the "regular" users can only view the data)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;((=&amp;gt; Alternatively, I will copy that app and in the copy (intended for everybody and specifically for that meeting), I'll just use&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AutoNumber() to replace all sensitive information so that that app does not have to be protected - but that is tricky and will take a&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; while since the sensitive info should then not be in the DataModel in the first place, so it has to be well thought thru.))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DataNibbler &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619105#M1265103</guid>
      <dc:creator>datanibbler</dc:creator>
      <dc:date>2026-01-26T18:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619106#M1265105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are using section access. Are you publishing the application using QV server are they user opening it with the desktop Client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can solve this by using NTNAME in section access and not USERID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 14:09:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619106#M1265105</guid>
      <dc:creator>Bill_Britt</dc:creator>
      <dc:date>2014-04-09T14:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619107#M1265107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes and yes and no:&lt;/P&gt;&lt;P&gt;- I am using SECTION_ACCESS.&lt;/P&gt;&lt;P&gt;- I donÄt have the QV_Publisher, only a QV_Server&lt;/P&gt;&lt;P&gt;- The users are opening the app in the Browser.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;NTNAME would be the Windows logon?&lt;/P&gt;&lt;P&gt;Hmm... could I simplify that a bit and just specify my own NTNAME for ADMIN access and just imply that all others have USER access, without explicitly stating every NTNAME?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DataNibbler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 14:15:08 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619107#M1265107</guid>
      <dc:creator>datanibbler</dc:creator>
      <dc:date>2014-04-09T14:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619108#M1265108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing to remember that anytime a document is open in server everyone is a "User" and no one is an "Administrator".&lt;/P&gt;&lt;P&gt;Yes, that would be the Windows login&lt;/P&gt;&lt;P&gt;Yes, You would use something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;Access&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="; color: #0000ff; font-size: 8pt;"&gt;&lt;STRONG&gt;LOAD&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; * &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;INLINE&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #800000; font-size: 8pt;"&gt;[&lt;BR /&gt;&amp;nbsp; ACCESS, NTNAME&lt;BR /&gt; ADMIN, YOURUSER&lt;BR /&gt;&amp;nbsp; USER, ME&lt;BR /&gt;&amp;nbsp; USER, BOSS&lt;BR /&gt;]&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="; color: #0000ff; font-size: 8pt;"&gt;&lt;STRONG&gt;Section&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff; font-size: 8pt;"&gt;Application&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 14:22:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619108#M1265108</guid>
      <dc:creator>Bill_Britt</dc:creator>
      <dc:date>2014-04-09T14:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619109#M1265109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had a similar problem to this and used a totally different method that provides you with security and availabilty:&lt;/P&gt;&lt;P&gt;You create additional columns on the Access table that can be used.&lt;/P&gt;&lt;P&gt;Create one called SECURE_ACCESS and set it to Y for yourself and N for all others.&lt;/P&gt;&lt;P&gt;You then put a conditional statement on the sheet of SECURE_ACCESS = 'Y'. This means that those people who allowed to see the sheet will do so and all others will not.&lt;/P&gt;&lt;P&gt;You can then go further to give access to a number of sheets by using buttons that would only appear if SECURE_ACCESS = 'Y' and these then make other sheets appear/disappear.&lt;/P&gt;&lt;P&gt;I hope that this helps - I have used it successfully in the past.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 15:39:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619109#M1265109</guid>
      <dc:creator>Roop</dc:creator>
      <dc:date>2014-04-09T15:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619110#M1265110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rupert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;of course that would be a possible method.&lt;/P&gt;&lt;P&gt;&amp;lt;=&amp;gt; My goal is not to have additional info in the SECTION ACCESS, but to somehow automatically fill the logon_data required by the SECTION ACCESS in the first place - but ONLY when the app is opened via document_chaining from that "morning_meeting_app".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@ Bill&lt;/P&gt;&lt;P&gt;The idea of using NTNAME for the SECTION ACCESS is good, that would avoid the logon_window. Only it is not sure that morning_meeting is always going to be held using the same user. - Well, I guess that would just be a question of "educating the users" &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'll try that out on a non_sensitive app.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DataNibbler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2014 08:25:56 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619110#M1265110</guid>
      <dc:creator>datanibbler</dc:creator>
      <dc:date>2014-04-10T08:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619111#M1265111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would guess education is the key here. You would have to put everyone in Section Access that might need to open the document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2014 11:12:51 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619111#M1265111</guid>
      <dc:creator>Bill_Britt</dc:creator>
      <dc:date>2014-04-10T11:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619112#M1265112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you are right. Educating the users is both very sensible and even necessary - we are now "going Germany" with QlikView and we're probably going to build everything centrally here. There is necessarily going to be a certain personell_buildup, but that is not going to happen between soo soon, so I just cannot afford any unnecessary spending of time.&lt;BR /&gt;Yesterday I spent a few hours actually duplicating the app and hiding personell_numbers with the AutoNumber() fct. and deleting SECTION_ACCESS from&lt;BR /&gt;the copy - but tonight I thought, why duplicate an app - that means double work, should any KPI come along to be implemented - which is more than probable.&lt;BR /&gt;So I will take the copy where I have already used AutoNumber() everywhere and delete the original and then put in SECTION_ACCESS again with NTNAME&lt;BR /&gt;&amp;nbsp; =&amp;gt; I will test this first and make a copy so I cannot by mistake lock myself out &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; That is one of the mistakes everyone makes once and hopefully not again ...&lt;/P&gt;&lt;P&gt;I also want to use the names - but to be included even in the DataModel ONLY for the HR dpt, so I'll include an OMIT field based on the NTNAME - matching the names to personell_numbers should be no problem since the AutoNumber() is as a rule only used in the very last and final table - all temp_tables are dropped again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;DataNibbler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 06:54:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619112#M1265112</guid>
      <dc:creator>datanibbler</dc:creator>
      <dc:date>2014-04-11T06:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619113#M1265113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one more problem:&lt;/P&gt;&lt;P&gt;=&amp;gt; I just tried to switch my SECTION_ACCESS from Username and password to NTNAME&lt;/P&gt;&lt;P&gt;&amp;lt;=&amp;gt; Though I have, in the document_properties, on the "security" tab, strictly limited what those persons classified&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as USER can do - they cannot save nor edit the script, for instance - they seem to be able to do just that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (since I don't know any other user who has a Client SW (except my colleague who is not here), I have added&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; myself as USER (after creating a backup copy)&lt;/P&gt;&lt;P&gt;&amp;lt;=&amp;gt; when opening the qvw in the client SW, I can still edit the script, save and "save as".&lt;/P&gt;&lt;P&gt;=&amp;gt; I have written SECTION_ACCESS like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACCESS, NTNAME&lt;/P&gt;&lt;P&gt;USER, DOMAIN\[name].[family_name]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(most users will view the apps in the browser so that their access_rights don't matter anyway, but there might be someone with a client installed)&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DataNibbler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 09:59:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619113#M1265113</guid>
      <dc:creator>datanibbler</dc:creator>
      <dc:date>2014-04-11T09:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619114#M1265114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to set the restrictions in the document properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.png" class="jive-image" src="https://community.qlik.com/legacyfs/online/57104_1.png" style="width: 620px; height: 494px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 14:09:24 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619114#M1265114</guid>
      <dc:creator>Bill_Britt</dc:creator>
      <dc:date>2014-04-11T14:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security issue</title>
      <link>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619115#M1265115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought of that. Still doesn't work.&lt;/P&gt;&lt;P&gt;Well, I'll just give it a few nights'&amp;nbsp; sleep and tell my colleague to test it again. It should work - there are regularly things on my machine that should actually work, with the correct syntax and all, but they don't - and then suddenly they do.&lt;/P&gt;&lt;P&gt;Thanks anyway!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DataNibbler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 14:59:04 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Security-issue/m-p/619115#M1265115</guid>
      <dc:creator>datanibbler</dc:creator>
      <dc:date>2014-04-11T14:59:04Z</dc:date>
    </item>
  </channel>
</rss>

