如何在BIRT BeforeFactory事件中用JS从CSV数据集验证报表权限
Got it, let's tackle this authorization requirement step by step. You're already set up with grabbing the user ID and getting the dataset handle—here's how to execute the dataset, check for the user's access, and block unauthorised users from generating the report:
Step 1: Full BeforeFactory Event Code
Replace your current code with this complete snippet (make sure to update the CSV data source name to match your actual report design):
// Get the user ID from the input parameter var userID = reportContext.getParameterValue("parm1"); reportContext.setGlobalVariable("userID", userID); // Get references to your CSV dataset and its corresponding data source var myDataSet = reportContext.getDesignHandle().findDataSet("Data Set CSV"); var csvDataSource = reportContext.getDesignHandle().findDataSource("YOUR_CSV_DATA_SOURCE_NAME"); // Replace with your actual data source name // Import required BIRT API classes importPackage(Packages.org.eclipse.birt.report.engine.api); importPackage(Packages.org.eclipse.birt.data.engine.api); // Create a dataset runner to execute the CSV dataset (BeforeFactory runs before automatic data fetching) var dataSetDefn = myDataSet.getQuery(); var runner = new DataSetRunner(dataSetDefn); runner.setDataSource(csvDataSource.getDataSource()); var isAuthorized = false; try { // Open the dataset and iterate through each row runner.open(); while (runner.next()) { // Extract the userid value from the current CSV row var userIdFromCSV = runner.getRowData().getColumnValue("userid"); // Check for a match (case-sensitive; add .toLowerCase() to both if you need case-insensitive comparison) if (userIdFromCSV === userID) { isAuthorized = true; break; // Exit loop early once we find a valid match } } } finally { // Always close the dataset to clean up resources, even if an error occurs runner.close(); } // Block report generation if user is not authorised if (!isAuthorized) { // Throw an error to immediately stop the report from being generated throw new Error("Unauthorized Access: User ID '" + userID + "' is not permitted to generate this report."); // Alternative: Hide report content and show a custom message (uncomment below if preferred) // var reportBody = reportContext.getDesignHandle().getBody(); // reportBody.setVisible(false); // var errorText = reportContext.getDesignHandle().getElementFactory().newTextItem(); // errorText.setContent("Unauthorized Access: You do not have permission to view this report."); // errorText.setStyleName("errorStyle"); // Create a bold/red style in your report design for this // reportBody.add(errorText); }
Key Notes to Keep in Mind
- Update the Data Source Name: Replace
YOUR_CSV_DATA_SOURCE_NAMEwith the exact name of your CSV data source in the report design—this is critical for the runner to access the CSV file. - Case Sensitivity: The code uses a case-sensitive match. If your CSV user IDs and input parameter values might have mixed cases, adjust the comparison to
userIdFromCSV.toLowerCase() === userID.toLowerCase(). - Resource Cleanup: The
finallyblock ensures the dataset is closed properly, preventing resource leaks in the BIRT Viewer. - Block Method Options: Throwing an error is the most direct way to abort report generation entirely. If you want to show a user-friendly message instead of an error page, use the alternative commented code to hide the report body and add a warning text.
- CSV File Access: Ensure the BIRT Viewer has read permissions for the
usrautho.txtfile, and that the file path in your CSV data source is correctly configured (absolute path or relative to the report design file).
Why This Works
In the BeforeFactory event, datasets aren't executed automatically—so we use DataSetRunner to manually run the CSV dataset, iterate through its rows, and verify the user ID. If the user isn't found in the authorized list, we either abort the report or modify the design to hide sensitive content.
内容的提问来源于stack exchange,提问作者Jean-Michel Hernandez

