Embedded to HyperPortal
For backend ussing standart aws library and QuickSIght module from it.
For frontend aws sdk for embedding.
API points in the HyperPortal
/v2-statistics/dashboards - returns list of dashboards this properties name, dahsboardId, updatedTime
/v2-statistics/dashboard-url/:dashboardId - return object with properties: dashoardId, url. Url wich we can use for open dashboard.
Limitation
Url of dashboard can be only openning once.
Token in the url valid 120 minutes. It's means that after this time dynamic filters won't work and you will see aws error after trying to use it.
Backend
That we can receive correct information for portal user from QuickSight, we need to authorize him to QS(QuickSight). For it, app should create user if it's missing on QS, and after it get temp aws credentials for user.
We created special Role with QS permissions in the aws: QuickSightEmbededRole - through which the user will be athourized on the aws. Also name of Role will be present in the name of user in the QS account.
Module QuickSight in the aws lib allows us to get user info, cerate user. Module documentation. Module STS allows to receive temp credentials for QS user.
Flow of user start working with QS we can see in the getUserCredentials in the libQuicksight.ts
Try to get user -> if user empty -> create user -> if group of tenant is empty -> create group -> add user to group -> receive credentials throught role which has only quicksight permissions. * Group needs to simple sharing dashboards for all BI users in the tanant.
const getUserCredentials = async (tenantId: string, userName: string): Promise<STS.Credentials> => {
let user = await getUser(tenantId, userName);
if (!user) {
user = await createUser(tenantId, userName);
if (!user) {
throw new Error('User error');
}
let group = await getGroup(tenantId);
if (!group) {
group = await createGroup(tenantId);
}
if (group && group.GroupName && user && user.UserName) {
await addUserToGroup(group.GroupName, user.UserName);
}
}
return getStsRoleCredentials(userName);
};