SBC Online Help
Breadcrumbs

Users

Purpose

Users are the core of the application and are managed via the Users page. The level of access to SBC is mainly defined by the role which is assigned to each user.

Overview Page

All users contained in SBC are displayed in a table view. The overview page supports basic functionality to create, edit, view or delete user entries or filtering the displayed data (see Working with the application).

The overview table displays only a subset of the most important user properties, which are:

  • Status (including SSO status)

  • User name

  • First name

  • Last name

  • Email Address

  • Company

  • Role

  • Organisation

  • Registration Date

Quick filters

Various Quick filters (accessible via the filter icon button) are available based on these criteria:

  • Subscribers

  • Inactive Subscriptions

  • Without Subscriptions

Selecting any of the above criteria displays only records that match the condition.

User Properties

User properties are organised into groups. The system administrator defines which properties are mandatory via the Sign Up settings.

Credentials

The credentials log you into the SBC web portal and and also into GNSS Spider Real-Time services via Ntrip, unless you set a separate “Ntrip user name” in the “Real-Time Service Access” section. Those parameters are mandatory.

Parameter

Description

User name

The user name uniquely identifies a user in the system.

Password


Enable Single Sign-On (SSO)

Enable Single Sign-On (SSO) authentication for this user. The user must already exist in the organisation's Identity Provider (IdP).

When this option is selected, the password is not required, as it is handled by the SSO-IdP.

The Email address must match the one on the SSO-IdP.

see Single Sign-On

Personal Information

Parameter

Description

Email address

Mandatory property

The email address must be unique across the system.

First name

Mandatory property

Last name

Mandatory property

Company

Mandatory property

Mobile phone


Job title


Language

The preferred UI language of the user.

The default is the system language set by the system administrator.

Account Information

Parameter

Description

Status

Three different states are supported:

  • Active

    • indicated by user solid full green

    • User can access and modify his profile and subscribe to articles from shop.

  • Pending

    • indicated by user solid full yellow

    • User cannot access his profiles until an administrative role activates it or the user activates it through the activation link sent to his email.

  • Inactive

    • indicated by user solid full red

    • User cannot access his profile. Only an administrative role can activate his profile.

The three keywords are also supported for filtering. Typing, e.g., “pending” displays all users with the related state.

See also Single Sign-On User status

Role

The user's role defines their permissions within the application. See Roles & Permissions

Organisation

The Organisation the user is a member of.

Registration Date

The account creation date.

Real-Time Service Access

The parameters of Real-Time Service Access define how users access Leica GNSS Spider's real-time services and authenticate themselves.

Most real-time services now use the Ntrip protocol with Ntrip authentication. If no specific “Ntrip user name” is set in this section, users connect using their main credentials (user name and password) for Ntrip services as well. This section's separate fields allow different Ntrip credentials than the web portal login. This lets administrative users, like those with the System Support role, view the Ntrip password, which isn't possible with the main credentials.

To support alternative authentication methods, fill in the corresponding fields.

Parameter

Description

Ntrip user name

Ntrip authentication type - user name

The value must be unique in the system.

Ntrip password

Ntrip authentication type - password

Dial-in authentication

Dial-in authentication type - telephone number

Use this option when RT-Products are provided by an access router or modem, and the GNSS Spider authentication type is set to telephone number. Enter the rover user's telephone number for dial-in authentication. Note that any change may cause rover user authentication to fail. The rover must also update accordingly. Telephone number format depends on the country and provider and may not require leading zeros or country codes.

The value must be unique in the system.

This legacy authentication type is no longer available in most countries.

Host address (IP v4)

Host adress authentication

Enter the rover user's host name or IPv4 address when the GNSS Spider authentication type is TCP/IP. Changing this may cause rover user authentication to fail. Update the rover accordingly.

The value must be unique in the system.

GPUID1

GPUID authentication

RT-Products configured in GNSS Spider with authentication type GPUID require two keys: GPUID1 and GPUID2. Enter the first key, GPUID1, here. It acts like a user name / identifier. The value must be unique in the system.

GPUID2

Enter the second key, GPUID2, here. It acs like a password / secret.

Rover inactivity validation [s]

Sets the number of seconds Leica GNSS Spider should hold the connection, after the last heartbeat is received from the user. The setting is used only, if the Spider RT-Product is of “Type” Automatic cell, Single cell or Nearest site, i.e., products that require a two-way communciation.

  • Enter a multiple of the NMEA-GGA message output rate of the rover equipment used by the user.

  • Enter 0 to disable the heartbeat check for this user for all connections to any RT-Product.

  • Default: 30 s

Example: Leica GS equipment’s NMEA-GGA rate is 10 s. With a tolerable loss of one message, a good setting would be 20 s. If the automatic closing of rover connections is used by a RT-Product in GNSS Spider, the connection of the user will be closed, if Spider does not receive a NMEA-GGA message for more than 20 s. This means if the user’s mobile network connection is interrupted, but the mobile network provider does not close the connection to Spider, Spider will close it after 20 s. The rover will be able to re-connect to Spider at the latest of 21 s after interruption, even with “Maximum simultaneous access” set to 1.

Real-Time Service Restrictions

Parameter

Description

Maximum simultaneous access

Sets the number of maximum simultaneous accesses for the user. Connections trying to access the RT product when the maximum number of connections is reached will be denied.

  • Default: 1

  • This setting does not affect the X-pos Post-Processing services.

  • In case of using limited SBC User Licenses, article no. 812426 to 812428, this value counts as number of SBC users and reduces the user license quota.

  • For the RT Product Type Single Rover (NMEA Redirect), multiple simultaneous access must be set to 1. Multiple simultaneous accesses greater than 1 are not allowed.

Note for Leica Spider Administrators:

The maximum simultaneous access settings can have an effect on rover connections and communication. See the Leica GNSS Spider online help topic "Watch view messages: Rover user communication" for more detailed information.

Data Handling & Privacy

Parameter

Description

Include in general connection log

Activate to include information of connect/disconnect for this user in the general connection log.

  • Default: enabled

General connection log must also be enabled on the Leica GNSS Spider Network Server (Tools > Configuration... > Connection logs).

Generate detailed connection logs

Activate to have Leica GNSS Spider generate a detailed connection log for this specific user.

  • Default: enabled

Detailed connection log must also be enabled on the Leica GNSS Spider Network Server (Tools > Configuration... > Connection logs).

Transfer detailed connection logs via FTP push

Activate to have Leica GNSS Spider push all detailed connection log files to a pre-set FTP location.

  • Default: disabled

FTP location for detailed connection log must also be selected on the Leica GNSS Spider Network Server (Tools > Configuration... > Connection logs).

Generate NMEA data logs

Activate to have Leica GNSS Spider generate a NMEA log for this specific user.

  • Default: disabled

NMEA log must also be enabled on the Leica GNSS Spider Network Server (Tools > Configuration... > Connection logs).

Display rover position in Live View

Activate to display the user with information received from user’s NMEA (position and more) in the Live Status / Map View. Otherwise the user stays incognito.

  • Default: enabled

  • It takes 1 hour until changes are considered by the Live Status.

Output rover position to reports

Activate to log the user’s position in Reporting. Otherwise the user stays incognito.

  • Default: enabled

Preferences

The Preferences section contains user specific settings for receiving Notifications and the favored Ntrip Caster.

The Preferred Ntrip Caster is used to inform SBC users about Caster connection details. It is shown to users who are logged in to SBC when they navigate to User Profile. The data is initially derived from the global Ntrip Caster Settings, but can also be changed by user to record any preferred Ntrip Caster connection data.

Parameter

Description

Enable email notification

By enabling the email option the user will receive automated notifications from the system as emails to the email address configured in the profile.

This option is enabled by default.

Ntrip Caster host name

This host name (e.g. ntrip.mycors.org) is usually used by the user account to access a real time data stream via Ntrip.

Ntrip Caster port

This port is used and shown as standard Ntrip caster port (e.g. 2101).

Additional Information

This section contains all dynamic user defined properties, that have been defined by the system administrator via the Sign Up

Single Sign-On

SBC supports SSO authentication through OpenID connect compliant Identity Providers (IdPs).

The SSO-IdP has to be configured as as part of the Spider Business Center (Identity Server) module (see Introduction). Once it is successfully configured, users that exist on that IdP can be added as users in SBC. They are then linked to SSO. The email address will be the unique user identifier. The password will be handled by the SSO-IdP. Once linked to the SSO, users can access the SBC web portal only through SSO login. Once linked to the SSO, users cannot be modified anymore to unlink it. The user needs to be deleted to unlink it from SBC.

When a user is marked inactive in the IdP for a period (e.g., because they resigned), they cannot log in. If marked active again (e.g., returning to the company), the user can access also SBC again.

SSO is recommended for all administrative users of SBC, typically members of the entity operating the GNSS reference station network. Staff leaving the organisation lose access to SBC immediately when disabled on the SSO. End users who use real-time and post-processing services usually have standard user accounts, not linked to SSO.

Single Sign-On User status

The status of a user that is linkend to a SSO is visualised in the overview table as an additional icon within the “Status” column.

The following SSO User statuses are supported:

Icon

Description

link solid full green


Successfully linked to SSO

User is created and active in the Identity Provider for SSO authentication, and is able to login into SBC

link solid full red



Problem with link to SSO

User is created in the IdP for SSO authentication, but is not allowed to access any of the Spider Software Suite services, including but not limited to:

  • Use any subscription activated services (real-time, post-processing)

  • SBC API

  • X-pos API

  • SBC web portal, unless IdP access is further granted on purpose (This action will trigger a reactivation of user, hence, access to the SBC Web portal will be granted again.)

Possible causes for not granting access to the Spider Software Services are:

  • User has been deleted in the IdP

  • User has been marked as disabled in the IdP

  • OAuth 2.0 access and refresh tokens of the user became invalid (Time interval previously configured in the IdP console)

  • IdP is not reachable anymore

    • When the entire Identity Provider system is down, then the users will be kept active and they will not be flagged as inactive in SBC. This is a preventive measure to avoid a huge workload to reactivate back the users in the event that the IdP system is up and running again.

none

Unlinked to SSO

The user is created in SBC (a standard SBC user) and not in the IdP, therefore SSO login via SBC is not permitted.