5 ms·
Well unfortunately that's just not how the real world works. In most production systems you are going to end up with a bunch of fields that aren't visible to re
by pathseeker 6y ago
Well unfortunately that's just not how the real world works. In most production systems you are going to end up with a bunch of fields that aren't visible to regular users. There ends up being a whole bunch of roles that need access to different levels and instead of implementing separate APIs for every user type, you just mask out the fields a specific type isn't allowed to see.
This is frequently called property level authorization or field level authorization.
https://stackoverflow.com/questions/30002351/enforcing-property-level-authorization-in-domain-objects https://stackoverflow.com/questions/30002351/enforcing-prope...
https://help.salesforce.com/articleView?id=security_data_access.htm&type=5 https://help.salesforce.com/articleView?id=security_data_acc...
You're just wording it in an indirect way to make it seem like something different. It's not "Using API key to determine what kind of information is returned", it's "hiding sensitive fields based on permissions".