☰
Current Page
Main Menu
Home
Home
Editing Security-Best-Practices
Edit
Preview
H1
H2
H3
default
Set your preferred keybinding
default
vim
emacs
markdown
Set this page's format to
AsciiDoc
Creole
Markdown
MediaWiki
Org-mode
Plain Text
RDoc
Textile
Rendering unavailable for
BibTeX
Pod
reStructuredText
Help 1
Help 1
Help 1
Help 2
Help 3
Help 4
Help 5
Help 6
Help 7
Help 8
Autosaved text is available. Click the button to restore it.
Restore Text
#Security Best Practices [[_TOC_]] ##Page Restriction Though you can hide buttons, it is still possible for a user to access pages such as the designer by directly entering the URL. As a part of tenant and user level security, you can add the code below to intercept the URL request and navigate them to a different page. In the examples below, we are checking the URL for the Report Designer. If the user attempted to access it from a report, it will redirect them to the report viewer, otherwise, it will redirect them to the report list page. This technique can be used for other pages such as the Dashboard Designer and Settings Page. **NOTE** If you are using the MVC kit, remove ".aspx" from the page references below. ### Code Sample ```csharp public static void InitializeReporting() { //Check to see if we've already initialized. if (HttpContext.Current.Session == null || HttpContext.Current.Session["ReportingInitialized"] != null) return; //Initialize System AdHocSettings.LicenseKey = "Insert License Key"; AdHocSettings.SqlServerConnectionString = @"Insert Connection String"; AdHocSettings.GenerateThumbnails = true; AdHocSettings.DashboardViewer = "Dashboards.aspx"; AdHocSettings.ShowSimpleModeViewer = true; AdHocSettings.IdentifiersRegex = "^.*[iI][Dd]$"; AdHocSettings.TabsCssUrl = "Resources/css/tabs.css"; AdHocSettings.ReportCssUrl = "Resources/css/Report.css"; AdHocSettings.ShowBetweenDateCalendar = true; AdHocSettings.AdHocConfig = new CustomAdHocConfig(); AdHocSettings.PrintMode = PrintMode.Html2PdfAndHtml; AdHocSettings.ChartingEngine = ChartingEngine.HtmlChart; AdHocSettings.UseBulkCSV = true; //Relevant Code Block if(!AdHocSettings.CurrentUserIsAdmin = false) { if (HttpContext.Current.Request.Url.ToString().Contains("ReportDesigner.aspx")) { if (!string.IsNullOrEmpty(HttpContext.Current.Request.Params["rn"])) { HttpContext.Current.Response.Redirect("ReportViewer.aspx?rn=" + HttpContext.Current.Request.Params["rn"]); } else { HttpContext.Current.Response.Redirect("ReportList.aspx"); } } } HttpContext.Current.Session["ReportingInitialized"] = true; } ```
Uploading file...
Header
 **This documentation is for the legacy Izenda 6 product. Documentation for the new Izenda 7 product can be found at [[https://www.izenda.com/docs/|https://www.izenda.com/docs/]]**
Sidebar
 --- * [[Izenda 7 Series Documentation|https://www.izenda.com/docs/]] * [[Release Notes]] * [[Upgrade Best Practices|FAQ/Izenda-Update-Best-Practices]] * [[FAQ]] * [[Tutorials]] * [[The Izenda API|/API/AdHocConfig]] * [[The AdHocSettings class|/API/AdHocSettings]] * [Developer Links and Guides](/Guides/Developer-Links-and-Guides) * [[Known Issues]] --- * <a href="http://www.izenda.com" rel="nofollow" target="_blank">Izenda Website</a> * [Product Video](https://www.youtube.com/watch?v=X3-yWFq0w5A) * <a href="http://www.izenda.com/blog" rel="nofollow" target="_blank">Izenda Blog</a> * <a href="http://www.izenda.com/company/" rel="nofollow" target="_blank">About Us</a> * <a href="http://www.izenda.com/contact-us/" rel="nofollow" target="_blank">Contact Us</a> --- * [Guide To Report Design](/Guides/ReportDesign) * [Making Custom Forms Video](http://www.youtube.com/watch?v=5b2axJlgdFs) --- * [[Acknowledgements]]
Edit message:
Cancel