Oracle Visual Builder: Applications That Outlive Their First Release · Module 11 · Security: who sees what
Securing business object endpoints
Lesson 114 of 176 · 3 min
Your own data, and THE DEFAULT THAT MAY BE WIDER THAN YOU ASSUMED. Checking WHAT AN ORDINARY SIGNED-IN USER CAN CALL. Module 5 Lesson 6 said creating a business object creates an endpoint. This is the security consequence, and the reason it is a separate lesson is that this endpoint is entirely yours to get wrong. A FUSION ENDPOINT COMES WITH SOMEBODY ELSE'S SECURITY MODEL ATTACHED. Yours comes with a default, and the default is typically that any authenticated user of the application can read it. "ANY AUTHENTICATED USER" IS A MUCH LARGER GROUP THAN THE PEOPLE YOUR PAGE IS FOR. Everybody who can sign in — other departments, other roles, contractors, whoever the application was rolled out to. Your page shows six fields of one customer's rows; the endpoint hands over every field of every row. AND IT IS INVISIBLE FROM INSIDE THE APPLICATION, WHICH IS WHY IT LASTS.…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Oracle Visual Builder: Applications That Outlive Their First Release, with a certificate on completion and a fourteen-day refund window.
In this module: Module 11 · Security: who sees what
- 1Where the trust boundary is
- 2Filtering in the UI is not securityFree preview
- 3Hiding a field sends it anyway
- 4Filter at the source
- 5Identity propagation, properly
- 6Roles inside your application
- 7Securing business object endpoints
- 8Secrets do not go in an application
- 9What ends up in a log or a URL
- 10What breaks: four security findings
- 11Lab briefing · Attack your own application
