Skip to content

The Statistics button

Every site in eodia analytics has a Statistics button. It opens an eodia insights dashboard that shows only that site, even to someone who would write free SQL in insights. The mechanism is the signed embedding that insights already knows how to verify: analytics signs a token, insights applies a row rule. No code in insights.

Create a group, “eodia analytics”, with read access to the analytics PostgreSQL source.

For this group, on each view of the analytics schema, a row rule:

site_id is equal to {{user.site_id}}

All views have site_id, including generated ones (evt_*, cls_*): add the rule to new views when they appear. A missing attribute closes access, as always in insights: without site_id, no rows.

Administration › Settings › Signed embedding: create a secret linked to this group. Note its identifier (the kid) and its value, shown only once.

Build the dashboards to open from analytics (audience, campaigns, e-commerce, attribution), with a “site” parameter (a filter on site_id). Note the identifier of each dashboard and that of its parameter.

Fenêtre de terminal
INSIGHTS_URL=https://insights.example.com
INSIGHTS_EMBED_KID=<the secret identifier>
INSIGHTS_EMBED_SECRET=<the secret value>
# INSIGHTS_EMBED_TTL=240 # token validity, in minutes

INSIGHTS_URL is also used by preview mode: it is the only origin the script listens to in order to draw a heatmap.

In Administration › Settings › insights connection, declare each dashboard:

FieldExample
insights identifierthe dashboard identifier
Label“Audience”, “Campaigns”, “E-commerce”
“Site” parameterthe identifier of the filter to lock to the site

With one dashboard, the Statistics button opens it; with several, it becomes a menu.

  1. analytics checks that the person has access to the site;
  2. it signs an HS256 JWT, with the kid in the header:
{
"resource": { "dashboard": "<insights identifier>" },
"params": { "<site parameter>": "<site_id>" },
"user": { "id": "analytics:<person>", "attributes": { "site_id": "<site_id>" } },
"exp": 1791158400
}
  1. it logs the opening (insights.open) and opens INSIGHTS_URL/embed?token=… in a new tab.

insights verifies the signature, reads the data with the privileges of the group linked to the secret, and applies the row rule with the token’s site_id attribute. The locked parameter is hidden: the person cannot switch to another site.

The token lifetime (4 hours by default) covers the session: insights checks the token again on each card execution. After that, a new click on Statistics signs another one.

Administration › Settings shows whether INSIGHTS_URL and INSIGHTS_EMBED_KID are set, and lists the declared dashboards. Open Statistics on a site, then, in insights, try to read another one: nothing must come out.

eodia analytics is free software by Eodia.