Capture app – Profile widget displays TEA values despite Sharing permissions and Program Rules

Hello DHIS2 Community,

We are testing DHIS2 2.41.6 and would like to clarify the expected behaviour of the Profile widget in the Capture app.

We have a national HIV Tracker program where some Tracked Entity Attributes (First Name, Last Name, National ID, Phone, etc.) are considered highly sensitive.

We performed the following tests:

  1. Sharing permissions

    • We removed access to the “First Name” and “Last Name” attributes for a specific user group.

    • Result:

      • The Capture TEI list correctly hides these attributes.

      • They are also unavailable in the column selector.

      • However, the Profile widget (right panel) still displays the values.

  2. Program Rules

    • We created a Program Rule using:
    d2:hasUserRole('USER_ROLE_UID')
    
    
    • Actions:

      • Hide First Name

      • Hide Last Name

      • Hide National ID

      • Hide Phone

    • Result:

      • The fields are correctly hidden in the edit form.

      • However, the Profile widget still displays the values.

Therefore, it appears that the Profile widget does not follow either:

  • TEA Sharing permissions, or

  • Program Rule “Hide Field” actions.

Questions

  1. Is this the expected behaviour of the Capture Profile widget?

  2. Is there any supported way to hide specific TEA values from the Profile widget for certain users?

  3. If not, would this be considered a bug or a feature request?

Our goal is to protect personally identifiable information in a national HIV implementation while allowing users to continue using the Capture application.

Thank you very much for your guidance.

Hi

@elmoujarrade , thank you for the detailed and clear post, and thanks for your patience.

This is a bug issue that has been addressed here: Jira (created by @YuryR and also confirmed in another ticket by @Karoline). Would you mind adding your comments to the Jira to confirm its priority in your HIV program?


I understand your goal completely, but if you don’t mind, I’m very curious to learn from you something that I don’t have a clear perspective on. So there are users who have access to the Capture app, the HIV program, and the TEIs in order to enter data, (which means they can access the TEAs because they are data entry users), right? What about these other users who have the same access but are not supposed to see the TEAs?

I want to understand the scenario a little bit better: is it that a data entry user “A” enters all the data including the TEAs but another data entry user “B” in the same facility with the same exact permissions, not supposed to be able to view the entries by user “A”? (Is this the scenario or is it something else?)

It would be great if you could answer my questions please! :folded_hands: Thanks!