matomo-org / matomo

Empowering People Ethically with the leading open source alternative to Google Analytics that gives you full control over your data. Matomo lets you easily collect data from websites & apps and visualise this data and extract insights. Privacy is built-in. Liberating Web Analytics. Star us on Github? +1. And we love Pull Requests!
https://matomo.org/
GNU General Public License v3.0
19.87k stars 2.65k forks source link

Anonymous View needs restrictions for Widgets & Dashboard #22380

Open DestructiveBurn opened 4 months ago

DestructiveBurn commented 4 months ago

Hello,

I was looking at the Widgets function and love the idea, but there is a major flaw that turns this feature useless to those who want to make only certain things public. To make this work publicly, the anonymous role needs to be set to "view" however, that makes everything public. I only want to make some things public, like the live map and real-time visitor count, not the entire dashboard.

I would like to suggest another option for the Anonymous account to restrict access to some features. Currently, the only options are "No Access" and "View". I like the idea of having some of the widgets publicly viewed on other sections of my site, but I don’t like the idea of having everything viewable, including the entire dashboard. I want to lock the dashboard with a “you don’t have permission to view this page” message if someone goes to https://example.com/matomo.

Adding "custom view" with the ability to enable or disable what you want for that account would be great. You have the option to select any part of the Widgetize reports to show in an iframe, so I am sure you could implement a restriction section for users. It's kinda pointless for Widgets if someone can just inspect the HTML, copy the URL from the iframe, and then enter it into the browser to see everything.

Hope to see this be a thing.

MatomoForumNotifications commented 3 months ago

This issue has been mentioned on Matomo forums. There might be relevant details there:

https://forum.matomo.org/t/anonymous-view-needs-restrictions-for-widgets-dashboard/58495/3

DestructiveBurn commented 3 months ago

This issue has been mentioned on Matomo forums. There might be relevant details there:

If you look under -- INFO -- you will see that's my post and to be clear I was told by your own staff member Philippe to post here.