The Statistics button
Every site in eodia analytics has a Statistics button. It opens an eodia insights dashboard that shows only that site, even to someone who would write free SQL in insights. The mechanism is the signed embedding that insights already knows how to verify: analytics signs a token, insights applies a row rule. No code in insights.
In eodia insights, once
Section titled “In eodia insights, once”1. A group
Section titled “1. A group”Create a group, “eodia analytics”, with read access to the analytics PostgreSQL source.
2. A row rule on each view
Section titled “2. A row rule on each view”For this group, on each view of the analytics schema, a row rule:
site_id is equal to {{user.site_id}}All views have site_id, including generated ones (evt_*, cls_*): add the rule to new
views when they appear. A missing attribute closes access, as always in insights: without
site_id, no rows.
3. An embedding secret
Section titled “3. An embedding secret”Administration › Settings › Signed embedding: create a secret linked to this group. Note its identifier (the kid) and its value, shown only once.
4. Dashboards
Section titled “4. Dashboards”Build the dashboards to open from analytics (audience, campaigns, e-commerce, attribution), with
a “site” parameter (a filter on site_id). Note the identifier of each dashboard and that of
its parameter.
In eodia analytics
Section titled “In eodia analytics”The variables
Section titled “The variables”INSIGHTS_URL=https://insights.example.comINSIGHTS_EMBED_KID=<the secret identifier>INSIGHTS_EMBED_SECRET=<the secret value># INSIGHTS_EMBED_TTL=240 # token validity, in minutesINSIGHTS_URL is also used by preview mode: it is the only origin the script listens to in
order to draw a heatmap.
The dashboards
Section titled “The dashboards”In Administration › Settings › insights connection, declare each dashboard:
| Field | Example |
|---|---|
| insights identifier | the dashboard identifier |
| Label | “Audience”, “Campaigns”, “E-commerce” |
| “Site” parameter | the identifier of the filter to lock to the site |
With one dashboard, the Statistics button opens it; with several, it becomes a menu.
What happens on click
Section titled “What happens on click”- analytics checks that the person has access to the site;
- it signs an HS256 JWT, with the
kidin the header:
{ "resource": { "dashboard": "<insights identifier>" }, "params": { "<site parameter>": "<site_id>" }, "user": { "id": "analytics:<person>", "attributes": { "site_id": "<site_id>" } }, "exp": 1791158400}- it logs the opening (
insights.open) and opensINSIGHTS_URL/embed?token=…in a new tab.
insights verifies the signature, reads the data with the privileges of the group linked to the
secret, and applies the row rule with the token’s site_id attribute. The locked parameter is
hidden: the person cannot switch to another site.
The token lifetime (4 hours by default) covers the session: insights checks the token again on each card execution. After that, a new click on Statistics signs another one.
Checking
Section titled “Checking”Administration › Settings shows whether INSIGHTS_URL and INSIGHTS_EMBED_KID are set, and
lists the declared dashboards. Open Statistics on a site, then, in insights, try to read
another one: nothing must come out.
eodia analytics is free software by Eodia.