Tuesday, March 20, 2012
Custom Security Roles
would like to use the report manager for rendering reports. What I don't
want to use is the built-in tools for item level and system level security.
Is there a way to get information as to which item is being accessed in the
Getpermissions and CheckAccess function so I can check my custom database for
authorization?Brent,
I don't think you need to know the item accessed because the CheckAccess
overload is scoped at an item level. In other words, if the user tries to
run a report A, the Report Server will pass the security descriptor for
report A only. The job of the security extension is to find out if the user
has rights to carry the action by examing the security descriptor. Any yes,
you can use application-defined role membership policies to simplify the
user maintanance.
I have a two-part article in the works for the SQL Magazine which discusses
Forms Authentication in detail. It should be out in January-February issues
I think.
--
Hope this helps.
---
Teo Lachev, MVP [SQL Server], MCSD, MCT
Author: "Microsoft Reporting Services in Action"
Publisher website: http://www.manning.com/lachev
Buy it from Amazon.com: http://shrinkster.com/eq
Home page and blog: http://www.prologika.com/
---
"Brent Slezak" <Brent Slezak@.discussions.microsoft.com> wrote in message
news:4614209E-953D-4A4B-B2BD-96EFE79FFDAC@.microsoft.com...
> I am trying to implement forms authentication in reporting services and I
> would like to use the report manager for rendering reports. What I don't
> want to use is the built-in tools for item level and system level
security.
> Is there a way to get information as to which item is being accessed in
the
> Getpermissions and CheckAccess function so I can check my custom database
for
> authorization?|||Teo,
First of all, I want to thank you for your prompt response to my question
and I will be looking for that article when it comes out.
Let me go into further detail as to the situation with the reporting
services and how I would like to use them. I currrently have a proprietary
security system setup for my enterprise-scale application that manages
thousands of users and groups and tens of thousands of roles. I don't want to
have to re-define that information in the ReportSErver database. Actually I
would like it if I had absolutly no security definition at all in the
ReportServer database. That being said. How would I get the unique
identifier of the object (i.e. report,folder,datasource) being accessed so
that I can cross-reference MyDatabase1 for security access.
In a nutshell I want to be able to use the report manager for the report
rendering and not for managing role-based security. I think building our own
custom rendering UI is the only logical alternative.
Please let me know what you would consider the best option with this scenario.
Thank you in advance for your input.
Brent
"Teo Lachev [MVP]" wrote:
> Brent,
> I don't think you need to know the item accessed because the CheckAccess
> overload is scoped at an item level. In other words, if the user tries to
> run a report A, the Report Server will pass the security descriptor for
> report A only. The job of the security extension is to find out if the user
> has rights to carry the action by examing the security descriptor. Any yes,
> you can use application-defined role membership policies to simplify the
> user maintanance.
> I have a two-part article in the works for the SQL Magazine which discusses
> Forms Authentication in detail. It should be out in January-February issues
> I think.
> --
> Hope this helps.
> ---
> Teo Lachev, MVP [SQL Server], MCSD, MCT
> Author: "Microsoft Reporting Services in Action"
> Publisher website: http://www.manning.com/lachev
> Buy it from Amazon.com: http://shrinkster.com/eq
> Home page and blog: http://www.prologika.com/
> ---
> "Brent Slezak" <Brent Slezak@.discussions.microsoft.com> wrote in message
> news:4614209E-953D-4A4B-B2BD-96EFE79FFDAC@.microsoft.com...
> > I am trying to implement forms authentication in reporting services and I
> > would like to use the report manager for rendering reports. What I don't
> > want to use is the built-in tools for item level and system level
> security.
> >
> > Is there a way to get information as to which item is being accessed in
> the
> > Getpermissions and CheckAccess function so I can check my custom database
> for
> > authorization?
>
>|||Brent,
I understand your scenario now. Of course, assuming that the reports will
be rendered on the server side of the application you don't have an issue
since you have an application front end. This is similar to the security
scenario I describe in Chapter 13 of my book.
However, the real problem is with URL addressability and custom security
extension. One approach that may be appropriate in your case is to get the
report path from the URL request. This could be similar to the approach I
describe in the following thread
http://groups.google.com/groups?q=Disable+Hyperlink+in+EXCEL&hl=en&lr=&selm=%23VCcwuh1EHA.1264%40TK2MSFTNGP12.phx.gbl&rnum=1
Once you get the report path, you can get the report identifier (the primary
key in table Catalgo) which is what you may want to use in your custom
security infrastructure.
--
Hope this helps.
---
Teo Lachev, MVP [SQL Server], MCSD, MCT
Author: "Microsoft Reporting Services in Action"
Publisher website: http://www.manning.com/lachev
Buy it from Amazon.com: http://shrinkster.com/eq
Home page and blog: http://www.prologika.com/
---
"Brent Slezak" <BrentSlezak@.discussions.microsoft.com> wrote in message
news:3741B21F-0963-457F-8EC6-A1F6403CB514@.microsoft.com...
> Teo,
> First of all, I want to thank you for your prompt response to my question
> and I will be looking for that article when it comes out.
> Let me go into further detail as to the situation with the reporting
> services and how I would like to use them. I currrently have a
proprietary
> security system setup for my enterprise-scale application that manages
> thousands of users and groups and tens of thousands of roles. I don't want
to
> have to re-define that information in the ReportSErver database. Actually
I
> would like it if I had absolutly no security definition at all in the
> ReportServer database. That being said. How would I get the unique
> identifier of the object (i.e. report,folder,datasource) being accessed so
> that I can cross-reference MyDatabase1 for security access.
> In a nutshell I want to be able to use the report manager for the report
> rendering and not for managing role-based security. I think building our
own
> custom rendering UI is the only logical alternative.
> Please let me know what you would consider the best option with this
scenario.
> Thank you in advance for your input.
> Brent
> "Teo Lachev [MVP]" wrote:
> > Brent,
> >
> > I don't think you need to know the item accessed because the CheckAccess
> > overload is scoped at an item level. In other words, if the user tries
to
> > run a report A, the Report Server will pass the security descriptor for
> > report A only. The job of the security extension is to find out if the
user
> > has rights to carry the action by examing the security descriptor. Any
yes,
> > you can use application-defined role membership policies to simplify the
> > user maintanance.
> >
> > I have a two-part article in the works for the SQL Magazine which
discusses
> > Forms Authentication in detail. It should be out in January-February
issues
> > I think.
> >
> > --
> > Hope this helps.
> >
> > ---
> > Teo Lachev, MVP [SQL Server], MCSD, MCT
> > Author: "Microsoft Reporting Services in Action"
> > Publisher website: http://www.manning.com/lachev
> > Buy it from Amazon.com: http://shrinkster.com/eq
> > Home page and blog: http://www.prologika.com/
> > ---
> >
> > "Brent Slezak" <Brent Slezak@.discussions.microsoft.com> wrote in message
> > news:4614209E-953D-4A4B-B2BD-96EFE79FFDAC@.microsoft.com...
> > > I am trying to implement forms authentication in reporting services
and I
> > > would like to use the report manager for rendering reports. What I
don't
> > > want to use is the built-in tools for item level and system level
> > security.
> > >
> > > Is there a way to get information as to which item is being accessed
in
> > the
> > > Getpermissions and CheckAccess function so I can check my custom
database
> > for
> > > authorization?
> >
> >
> >
Monday, March 19, 2012
Custom Report Item example not rendering right?
I'm trying to work with the custom report item example (PolygonsCRI.dll) from the latest SQL Server 2005 downloads. I've followed all of the instructions on how to deploy the report. The report is now available on my Report Server, and I can load the Polygons.sln report and view it in the designer. However, whenever I preview the report in the designer or view the report on the server, the polygon report items just show up as big blank spots - there's no image there and no indication of an error. The chart on the report renders just fine, though.
Does anybody have any ideas on what could be causing this?
Thanks,
Glenn Burnsider
There is a typo in the PolygonsCRI.vb and .cs file. The class name should be "PolygonsCRI", not "PolygonsCCustomReportItem". Change the class name to "PolygonsCRI", redeploy, and the chart should be visible now.Custom Report Item example not rendering right?
I'm trying to work with the custom report item example (PolygonsCRI.dll) from the latest SQL Server 2005 downloads. I've followed all of the instructions on how to deploy the report. The report is now available on my Report Server, and I can load the Polygons.sln report and view it in the designer. However, whenever I preview the report in the designer or view the report on the server, the polygon report items just show up as big blank spots - there's no image there and no indication of an error. The chart on the report renders just fine, though.
Does anybody have any ideas on what could be causing this?
Thanks,
Glenn Burnsider
There is a typo in the PolygonsCRI.vb and .cs file. The class name should be "PolygonsCRI", not "PolygonsCCustomReportItem". Change the class name to "PolygonsCRI", redeploy, and the chart should be visible now.Custom Rendering Extension in SQL 2000 Reporting Services
version of Reporting Services. The documentation I found on MSDN indicates
that it is possible to write one using Visual Studio .Net 2003 (which is what
I'm using). The samples they have are for VS.Net 2005. I'm trying to
implement it for VS.Net 2003, and I can't seem to find the references for:
Microsoft.ReportingServices.ReportRendering.IRenderingExtension
in SQL 2000 Reporting Services. What is the equivalent in SQL Server 2000
RS and Visual Studio .Net 2003?
Thanks,
Mike SandwickMicrosoft.ReportingServices.ReportRendering.IRenderingExtension is identical
in RS 2000 and RS 2005. In RS 2000 you need to add a reference to
Microsoft.ReportingServices.Processing.dll, in the final RS 2005 release it
would be Microsoft.ReportingServices.ProcessingCore.dll.
-- Robert
This posting is provided "AS IS" with no warranties, and confers no rights.
"Mike Sandwick" <MikeSandwick@.discussions.microsoft.com> wrote in message
news:F9A76586-30EE-450D-993E-7FEE3ADA1BF3@.microsoft.com...
>I am trying to write a custom rendering extension for the SQL Server 2000
> version of Reporting Services. The documentation I found on MSDN
> indicates
> that it is possible to write one using Visual Studio .Net 2003 (which is
> what
> I'm using). The samples they have are for VS.Net 2005. I'm trying to
> implement it for VS.Net 2003, and I can't seem to find the references for:
> Microsoft.ReportingServices.ReportRendering.IRenderingExtension
> in SQL 2000 Reporting Services. What is the equivalent in SQL Server 2000
> RS and Visual Studio .Net 2003?
> Thanks,
> Mike Sandwick|||Thanks, Robert. This is exactly the information I was looking for! I added
the reference to Microsoft.ReportingServices.Processing.dll, and I can now
compile the sample.
Thanks,
Mike Sandwick
"Robert Bruckner [MSFT]" wrote:
> Microsoft.ReportingServices.ReportRendering.IRenderingExtension is identical
> in RS 2000 and RS 2005. In RS 2000 you need to add a reference to
> Microsoft.ReportingServices.Processing.dll, in the final RS 2005 release it
> would be Microsoft.ReportingServices.ProcessingCore.dll.
>
> -- Robert
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Mike Sandwick" <MikeSandwick@.discussions.microsoft.com> wrote in message
> news:F9A76586-30EE-450D-993E-7FEE3ADA1BF3@.microsoft.com...
> >I am trying to write a custom rendering extension for the SQL Server 2000
> > version of Reporting Services. The documentation I found on MSDN
> > indicates
> > that it is possible to write one using Visual Studio .Net 2003 (which is
> > what
> > I'm using). The samples they have are for VS.Net 2005. I'm trying to
> > implement it for VS.Net 2003, and I can't seem to find the references for:
> >
> > Microsoft.ReportingServices.ReportRendering.IRenderingExtension
> >
> > in SQL 2000 Reporting Services. What is the equivalent in SQL Server 2000
> > RS and Visual Studio .Net 2003?
> >
> > Thanks,
> > Mike Sandwick
>
>
Custom Rendering Extension for HTML Fields
I am using RS 2005, a "comments" field in a database contains HTML content. When rendering the field on the report it displays raw HTML.
Does anybody knows about a custom rendering extension that will render HTML content?
Thanks
Fernando
Has anyone resolved this? I am facing a similar issue. My website has form that takes comments via FreeTextBox. It is probably similar to what is used on this FORUM! The FreeTextBox control returns text with HTML tags throughout. I need to display the same data via Reporting Services. Currently using SQL Server 2000, Migrating to 2005 soon.
This has to be a common scenario. How about a third party control?
Thanks.
|||This is currently not supported. See http://blogs.msdn.com/bimusings/archive/2005/12/14/503648.aspx. We are working on this for an upcoming release.
Custom Rendering Extension for HTML Fields
I am using RS 2005, a "comments" field in a database contains HTML content. When rendering the field on the report it displays raw HTML.
Does anybody knows about a custom rendering extension that will render HTML content?
Thanks
Fernando
Has anyone resolved this? I am facing a similar issue. My website has form that takes comments via FreeTextBox. It is probably similar to what is used on this FORUM! The FreeTextBox control returns text with HTML tags throughout. I need to display the same data via Reporting Services. Currently using SQL Server 2000, Migrating to 2005 soon.
This has to be a common scenario. How about a third party control?
Thanks.
|||This is currently not supported. See http://blogs.msdn.com/bimusings/archive/2005/12/14/503648.aspx. We are working on this for an upcoming release.
Custom Rendering Extension for HTML Fields
I am using RS 2005, a "comments" field in a database contains HTML content. When rendering the field on the report it displays raw HTML.
Does anybody knows about a custom rendering extension that will render HTML content?
Thanks
Fernando
Has anyone resolved this? I am facing a similar issue. My website has form that takes comments via FreeTextBox. It is probably similar to what is used on this FORUM! The FreeTextBox control returns text with HTML tags throughout. I need to display the same data via Reporting Services. Currently using SQL Server 2000, Migrating to 2005 soon.
This has to be a common scenario. How about a third party control?
Thanks.
|||This is currently not supported. See http://blogs.msdn.com/bimusings/archive/2005/12/14/503648.aspx. We are working on this for an upcoming release.
Custom Rendering Example.
renderer? Or are there any third party renderers available?
Thanks.
Satish.In case anyone is looking for the same i found one in MSDN mag
http://msdn.microsoft.com/msdnmag/issues/05/02/CustomRenderers/
Satish wrote:
> Does anyone know of any code example available for writing a custom
> renderer? Or are there any third party renderers available?
> Thanks.
> Satish.
Custom Rendering
I want to "create" a renderer for RS (2000). I read some articles on
this topic, and i found this technical sample for RS 2005 :
Display Your Data Your Way with Custom Renderers for Reporting Services
:
http://msdn.microsoft.com/msdnmag/issues/05/02/CustomRenderers/default.aspx
I've read int this newsgroup the way to implement the rendreing is the
same in RS 2000.
I can compile my customized renderer, but when i look at my reports, i
don't see my renderer in the ouputs dropdownlist... I have modified the
"RSReportServer.config" and "rssrvpolicy.config" files, as its written
in the article. I tried IISRESET, and I even restart the server, but no
changes.
Does this sample really work in RS 2000 ?
If yes, do you have any suggestion to resolve my problem ?I'm back to give more information about my problem.
Here's what i found in the report server log file (sorrry, some words
are French) :
w3wp!extensionfactory!ca0!06/07/2005-15:52:05:: e ERROR: Exception
caught instantiating report server extension:
System.Security.SecurityException: =C9chec de la demande pour une
autorisation de type
System.Security.Permissions.StrongNameIdentityPermission, mscorlib,
Version=3D1.0.5000.0, Culture=3Dneutral, PublicKeyToken=3Db77a5c561934e089.
at
XXX.ReportingServices.CustomHTMLRendering.CustomRenderer.SetConfiguration(S=tring
configuration)
at
Microsoft.ReportingServices.Diagnostics.ExtensionClassFactory.GetNewExtensi=onInstance(String
extensionName, String extensionType)
L'=E9tat de l'autorisation qui a =E9chou=E9 =E9tait :
<IPermission
class=3D"System.Security.Permissions.StrongNameIdentityPermission,
mscorlib, Version=3D1.0.5000.0, Culture=3Dneutral,
PublicKeyToken=3Db77a5c561934e089"
version=3D"1"
PublicKeyBlob=3D"0024000004800000940000000602000000240000525341310004000001=000100272736AD6E5F9586BAC2D531EABC3ACC666C2F8EC879FA94F8F7B0327D2FF2ED52344=8F83C3D5C5DD2DFC7BC99C5286B2C125117BF5CBE242B9D41750732B2BDFFE649C6EFB8E552=6D526FDD130095ECDB7BF210809C6CDAD8824FAA9AC0310AC3CBA2AA0523567B2DFA7FE250B=30FACBD62D4EC99B94AC47C7D3B28F1F6E4C8"/>
.
It seems that my assembly mscorlib can't be called, or that mscorlib
can't access something.
I don't understand really this error. Can somebody help me ?
Thanks.