Oracle Visual Builder: Applications That Outlive Their First Release · Module 11 · Security: who sees what
What ends up in a log or a URL
Lesson 116 of 176 · 3 min
IDENTIFIERS AND PERSONAL DATA in query strings, browser history and your own logging. WHAT IS RETAINED, AND BY WHOM. Data does not only leak through responses. It leaks by being written somewhere durable that nobody thinks of as storage. A URL IS THE MOST COPIED THING IN ANY APPLICATION. It is in browser history, in bookmarks, in the referrer sent to other sites, in server access logs, and in the message somebody pastes to a colleague to say "look at this". Anything in a query string is in all of those, indefinitely, outside every protection your application has. WHICH MAKES THE RULE SIMPLE: PUT AN IDENTIFIER IN A URL, NEVER PERSONAL DATA. A record id is fine — opening it still requires permission. A name, an email address, a national identifier or a salary in a query string has been written into half a dozen logs nobody controls, and pasting…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Oracle Visual Builder: Applications That Outlive Their First Release, with a certificate on completion and a fourteen-day refund window.
In this module: Module 11 · Security: who sees what
- 1Where the trust boundary is
- 2Filtering in the UI is not securityFree preview
- 3Hiding a field sends it anyway
- 4Filter at the source
- 5Identity propagation, properly
- 6Roles inside your application
- 7Securing business object endpoints
- 8Secrets do not go in an application
- 9What ends up in a log or a URL
- 10What breaks: four security findings
- 11Lab briefing · Attack your own application
