This discussion is archived
4 Replies Latest reply: Dec 4, 2012 6:24 AM by AmithY RSS

Question on GROUP Session variable

AmithY Expert
Currently Being Moderated
Hi All,

OBIEE Version: 10g

I have a question on using the GROUP session variable, and I am seeing some weird behavior. Authentication is done using LDAP's setup in the RPD. The group's are not retrieved from the LDAP. I have created a new init block to populate the group's information from an external table. The variable does get populated correctly, I checked this by running a query in the front end on the session variable.

However, the group name doesn't appear in the list of groups under My Account. I have a data filter setup on the group named exactly the same I am assigned to, and the filter doesn't get applied either. If I create a catalog group with same name, then the group name appears in the list of groups I am part of under My Account.

Can anyone tell me if it is even possible to combine authentication from ldap's and authorization (Assigning user to groups) from external table?

Thanks,
A-Y.
  • 1. Re: Question on GROUP Session variable
    Srini VEERAVALLI Guru
    Currently Being Moderated
    I would like to check very first 'Required for authentication' and with Row-wise initialization for group init block

    If everything is fine then can I have a look at your rpd try to send me email.
    You can delete all objects related to all 3 layers if you want.
  • 2. Re: Question on GROUP Session variable
    AmithY Expert
    Currently Being Moderated
    Veeravalli wrote:
    I would like to check very first 'Required for authentication' and with Row-wise initialization for group init block

    If everything is fine then can I have a look at your rpd try to send me email.
    You can delete all objects related to all 3 layers if you want.
    Yes, required for authentication is set and variable is row-wise initialized also. I just found out there is a bug related to this which I think is causing the issue. Not sure if there is a patch available for it. Bug # 13428124
  • 3. Re: Question on GROUP Session variable
    Srini VEERAVALLI Guru
    Currently Being Moderated
    I forgot to mentioned one more check; Execution Precedence right after LDAP auth for this group init block.

    I dont think groups are create automatically as User creation in catalog, we have to create groups manually in catalog with same name as in rpd or as in database.

    I dont thing there is anything wrong in your rpd.

    Edited by: Veeravalli on Nov 28, 2012 2:01 PM
  • 4. Re: Question on GROUP Session variable
    AmithY Expert
    Currently Being Moderated
    Thanks Srini. The issue turned out to be a bug. I developed a workaround for next few months, as 11g will soon be in place, and will be using application roles then. Thanks for your help! I still owe you an email.

Legend

  • Correct Answers - 10 points
  • Helpful Answers - 5 points