Oracle Visual Builder: Applications That Outlive Their First Release · Module 11 · Security: who sees what
Identity propagation, properly
Lesson 112 of 176 · 2 min
Calling Fusion AS THE SIGNED-IN USER so their own security applies. Why this is THE ANSWER TO MOST OF THIS MODULE AT ONCE. Module 6 Lesson 3 presented this as an authentication choice. Here it is the security architecture, and the reason it deserves its own lesson is that it solves several problems simultaneously rather than one. WITH THE USER'S OWN IDENTITY, FUSION APPLIES THE SECURITY SOMEBODY ALREADY DESIGNED. Data security policies, role assignments, the rules a security team maintains and audits. Your application inherits all of it and has to reproduce none of it. WHICH CLOSES LESSON 2 AND LESSON 4 TOGETHER. Ask for another department's rows and the response is empty, because Fusion refuses — not because your page filtered. The restriction is on the far side of the boundary and cannot be edited. IT LARGELY CLOSES LESSON 3 TOO. Fields the user may not see are frequently…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Oracle Visual Builder: Applications That Outlive Their First Release, with a certificate on completion and a fourteen-day refund window.
In this module: Module 11 · Security: who sees what
- 1Where the trust boundary is
- 2Filtering in the UI is not securityFree preview
- 3Hiding a field sends it anyway
- 4Filter at the source
- 5Identity propagation, properly
- 6Roles inside your application
- 7Securing business object endpoints
- 8Secrets do not go in an application
- 9What ends up in a log or a URL
- 10What breaks: four security findings
- 11Lab briefing · Attack your own application
