MSAMM
Back to course

Oracle Visual Builder: Applications That Outlive Their First Release · Module 11 · Security: who sees what

Securing business object endpoints

Lesson 114 of 176 · 3 min

Your own data, and THE DEFAULT THAT MAY BE WIDER THAN YOU ASSUMED. Checking WHAT AN ORDINARY SIGNED-IN USER CAN CALL. Module 5 Lesson 6 said creating a business object creates an endpoint. This is the security consequence, and the reason it is a separate lesson is that this endpoint is entirely yours to get wrong. A FUSION ENDPOINT COMES WITH SOMEBODY ELSE'S SECURITY MODEL ATTACHED. Yours comes with a default, and the default is typically that any authenticated user of the application can read it. "ANY AUTHENTICATED USER" IS A MUCH LARGER GROUP THAN THE PEOPLE YOUR PAGE IS FOR. Everybody who can sign in — other departments, other roles, contractors, whoever the application was rolled out to. Your page shows six fields of one customer's rows; the endpoint hands over every field of every row. AND IT IS INVISIBLE FROM INSIDE THE APPLICATION, WHICH IS WHY IT LASTS.

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Oracle Visual Builder: Applications That Outlive Their First Release, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 11 · Security: who sees what

  1. 1Where the trust boundary is
  2. 2Filtering in the UI is not securityFree preview
  3. 3Hiding a field sends it anyway
  4. 4Filter at the source
  5. 5Identity propagation, properly
  6. 6Roles inside your application
  7. 7Securing business object endpoints
  8. 8Secrets do not go in an application
  9. 9What ends up in a log or a URL
  10. 10What breaks: four security findings
  11. 11Lab briefing · Attack your own application