能否将ShinyProxy登录信息传递至Shiny App并实现用户数据过滤?
Hey there! Both of your questions have straightforward, practical solutions—let’s break them down step by step.
1. Passing the Login Username to Your Shiny App
ShinyProxy makes it easy to inject the logged-in user’s username directly into your Shiny App using environment variables. Here’s how:
Step 1: Configure ShinyProxy’s application.yml
In your ShinyProxy configuration file, add an env section under your app definition to pass the username as an environment variable. The #{proxy.userId} placeholder will automatically populate with the logged-in user’s ID/username:
apps: - name: your-shiny-app display-name: Your Custom App docker-cmd: ["R", "-e", "shiny::runApp('/app')"] docker-image: your-shiny-image:latest env: APP_USERNAME: "#{proxy.userId}"
Step 2: Retrieve the Username in Your Shiny App
Inside your Shiny App code, use Sys.getenv() to pull the username from the environment:
# Get the logged-in username current_user <- Sys.getenv("APP_USERNAME") # Use it in your app (e.g., welcome message) shinyApp( ui = fluidPage(h1(paste("Welcome,", current_user))), server = function(input, output) {} )
2. Passing Full Login Details for SQL Filtering
You can extend the above approach to pass additional user attributes (like email, roles, or custom metadata) and use them to filter SQL queries safely.
Step 1: Pass Additional User Attributes in ShinyProxy
Depending on your authentication setup (LDAP, OAuth, etc.), ShinyProxy has access to extra user details. Pass these as environment variables in application.yml:
apps: - name: your-shiny-app display-name: Your Custom App docker-cmd: ["R", "-e", "shiny::runApp('/app')"] docker-image: your-shiny-image:latest env: USER_ID: "#{proxy.userId}" USER_EMAIL: "#{proxy.userAuthentication.name}" USER_ROLES: "#{proxy.userAuthentication.authorities}"
#{proxy.userId}: The user’s unique ID/username#{proxy.userAuthentication.name}: Typically the user’s email (depends on your auth provider)#{proxy.userAuthentication.authorities}: Comma-separated list of the user’s roles
Step 2: Use the Details for Secure SQL Filtering
In your Shiny App, retrieve these variables and use parameterized queries (critical to avoid SQL injection) to fetch user-specific data:
library(DBI) library(RPostgres) # Or your DB driver of choice # Get user details from environment variables user_id <- Sys.getenv("USER_ID") user_email <- Sys.getenv("USER_EMAIL") # Connect to your database db_con <- dbConnect( RPostgres::Postgres(), dbname = "your_db", host = "db_host", user = "db_user", password = "db_password" ) # Use a parameterized query to filter data safely safe_query <- "SELECT * FROM user_specific_data WHERE user_id = $1" user_data <- dbGetQuery(db_con, safe_query, params = list(user_id)) # Clean up the connection dbDisconnect(db_con) # Build your Shiny UI/Server with the filtered data shinyApp( ui = fluidPage( h1(paste("Your Data,", user_email)), tableOutput("user_table") ), server = function(input, output) { output$user_table <- renderTable(user_data) } )
Always use parameterized queries instead of string concatenation—this prevents malicious users from exploiting SQL injection vulnerabilities.
内容的提问来源于stack exchange,提问作者Balajee

