Oracle Visual Builder: Applications That Outlive Their First Release · Module 11 · Security: who sees what
What breaks: four security findings
Lesson 117 of 176 · 3 min
A TABLE FILTERED IN THE BROWSER, A HIDDEN FIELD IN THE PAYLOAD, A BUSINESS OBJECT ANYONE COULD CALL, and A KEY IN THE PAGE SOURCE. THE TABLE FILTERED IN THE BROWSER IS THE COMMONEST AND THE ONE WITH THE LEAST INTENT BEHIND IT. Fetch everything, filter in the page, show one department. Lesson 2, and every screen is correct while every other department's rows sit in the response — and the rows filtered out are the ones the filter existed to protect. THE HIDDEN FIELD IS THE SAME DEFECT AND SURPRISES PEOPLE MORE. A column hidden by role, its values in every row of the payload. Lesson 3: hiding is drawing, not withholding, and the field people hide is usually the field that matters — a salary, a margin, a personal identifier. THE BUSINESS OBJECT ANYONE COULD CALL IS THE ONE NOBODY DECIDED. An object created, an endpoint created with…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Oracle Visual Builder: Applications That Outlive Their First Release, with a certificate on completion and a fourteen-day refund window.
In this module: Module 11 · Security: who sees what
- 1Where the trust boundary is
- 2Filtering in the UI is not securityFree preview
- 3Hiding a field sends it anyway
- 4Filter at the source
- 5Identity propagation, properly
- 6Roles inside your application
- 7Securing business object endpoints
- 8Secrets do not go in an application
- 9What ends up in a log or a URL
- 10What breaks: four security findings
- 11Lab briefing · Attack your own application
