Skip to content

User ^v2.7.0 ​

A user account, with its security groups, access levels and application tags.

js
const user = userSecurity.users.getCurrent();

if (!user.hasGroup("Finance")) {
    user.addGroup("Finance");
}

Constructor ​

Returned by userSecurity.users and by security.application(...).users. It can't be created directly.

Overview ​

  • Groups by name or object: methods that take a group accept its name or a Group.
  • Access levels: access levels are "NO_ACCESS", "READ_ACCESS" or "WRITE_ACCESS".
  • Object types: object access levels use "CUBES", "CARDS", "WORKVIEWS", "DIMENSIONS", "PROCESSES", "SCHEDULES", "TABLES", "APPLICATIONS", "MAPPINGS" or "VARIABLES".

Methods ​

getId getId() number ​

Returns the user's id.

getName getName() string ​

Returns the user's name.

getEmail getEmail() string ​

Returns the user's email address.

getRole getRole() string ​

Returns the user's role, such as "MODELLER", "COLLABORATOR" or "ANALYST".

isTwoFactorEnabled isTwoFactorEnabled() boolean ​

Returns true when the user has two-factor authentication turned on.

groups groups() object ​

Returns the user's groups, as an object with primary_group and groups.

hasGroup hasGroup(group) boolean ​

Returns true when the user is in a group.

ParameterTypeDescription
groupstring | GroupThe group's name, or the group.

hasAdminGroup hasAdminGroup() boolean ​

Returns true when the user is in the admin group.

addGroup addGroup(group) boolean ​

Adds the user to a group. Returns true when they were added.

ParameterTypeDescription
groupstring | GroupThe group's name, or the group.

removeGroup removeGroup(group) boolean ​

Removes the user from a group. Returns true when they were removed.

ParameterTypeDescription
groupstring | GroupThe group's name, or the group.

setPrimaryGroup setPrimaryGroup(group) boolean ​

Sets the user's primary group. Returns true when it changed.

ParameterTypeDescription
groupstring | GroupThe group's name, or the group.

clearGroups clearGroups() boolean ​

Removes the user from every group.

getModelAccessLevel getModelAccessLevel(modelIdOrName) string ​

Returns the user's access level for a model, across all of their groups.

ParameterTypeDescription
modelIdOrNamestringThe model's name or id.

getObjectAccessLevel getObjectAccessLevel(modelIdOrName, objectType, objectKey, breakOnAccessLevel) string ​

Returns the user's access level for one object in a model.

ParameterTypeDescription
modelIdOrNamestringThe model's name or id.
objectTypestringThe object type. See the list of object types.
objectKeystringThe object's name or id.
breakOnAccessLevelstringOptional. Stops checking once this access level is reached.

getElementAccessLevel getElementAccessLevel(modelIdOrName, dimensionIdOrName, elementName, breakOnAccessLevel) string ​

Returns the user's access level for an element in a dimension.

ParameterTypeDescription
modelIdOrNamestringThe model's name or id.
dimensionIdOrNamestringThe dimension's name or id.
elementNamestringThe element's name.
breakOnAccessLevelstringOptional. Stops checking once this access level is reached.

Access Tag Methods ^v2.7.212 ​

tags tags(application) array ​

Returns the user's ElementTag and ScreenTag tags in an application.

ParameterTypeDescription
applicationstringThe application's name or id.

elementTags elementTags(application) array ​

Returns the user's ElementTag tags in an application.

ParameterTypeDescription
applicationstringThe application's name or id.

screenTags screenTags(application) array ​

Returns the user's ScreenTag tags in an application.

ParameterTypeDescription
applicationstringThe application's name or id.

hasTag hasTag(application, tagNameOrId) boolean ​

Returns true when the user has a tag in an application.

ParameterTypeDescription
applicationstringThe application's name or id.
tagNameOrIdstringThe tag's name or id.

hasTag hasTag(tag) boolean ​

Returns true when the user has a tag.

ParameterTypeDescription
tagElementTag | ScreenTagThe tag.

addTag addTag(application, tag) boolean ​

Gives the user a tag in an application. Returns true when it was added.

ParameterTypeDescription
applicationstringThe application's name or id.
tagstring | ElementTag | ScreenTagThe tag's name or id, or the tag.

removeTag removeTag(application, tag) boolean ​

Removes a tag from the user in an application. Returns true when it was removed.

ParameterTypeDescription
applicationstringThe application's name or id.
tagstring | ElementTag | ScreenTagThe tag's name or id, or the tag.

setTags setTags(application, tags) boolean ​

Replaces the user's tags in an application. Tags not in the list are removed.

ParameterTypeDescription
applicationstringThe application's name or id.
tagsarrayTag names, or tags.

clearTags clearTags(application) boolean ​

Removes all of the user's tags in an application.

ParameterTypeDescription
applicationstringThe application's name or id.

getElementAccessTagLevel getElementAccessTagLevel(application, dimension, element) string ​

Returns the access level the user's tags give them for an element in a dimension.

ParameterTypeDescription
applicationstringThe application's name or id.
dimensionstringThe dimension's name or id.
elementstringThe element's name.

getAvailableScreens getAvailableScreens(application) array ​

Returns the ApplicationScreen screens the user's tags give them access to.

ParameterTypeDescription
applicationstringThe application's name or id.

hasAvailableScreen hasAvailableScreen(application, screenIdOrName) boolean ​

Returns true when the user's tags give them access to a screen. Returns false when the screen doesn't exist.

ParameterTypeDescription
applicationstringThe application's name or id.
screenIdOrNamestringThe screen's id or title.

Examples ​

Manage a user's groups ​

js
const user = userSecurity.users.getCurrent();

console.log("Is user in Test Group? " + (user.hasGroup("Test Group") ? "Yes" : "No"));

const added = user.addGroup("Example Group");
console.log("User added to Example Group: " + (added ? "Successful" : "Failed"));

const removed = user.removeGroup("Example Group");
console.log("User removed from Example Group: " + (removed ? "Successful" : "Failed"));

console.log("User Groups: ", user.groups());

Check a user's access ​

js
const user = userSecurity.users.getFromEmail("user@example.com");

if (user.getModelAccessLevel("Sales Model") === "NO_ACCESS") {
    script.fail(user.getName() + " can't access the Sales Model.");
}

Give a user an application's tags ​

js
const user = userSecurity.users.getFromEmail("user@example.com");

user.setTags("Planning", ["North Region", "Finance Screens"]);
console.log(user.tags("Planning"));