Skip to main content

Using this app:

https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FR6GaUAL&placement=a0d3u00000B363BAAR&tab=r

 

Generally our communities don't use the out of the box profiles and we don't grant guest users access to anything (except the basics like login page provided by sfdc).

 

The report from this app seems to reflect that just fine. But there is a large section on ApexClasses that may or may not include AuraEnabled methods all flagged as potential risk. Nearly all of these come from managed packages.

 

My questions are:

  1. None of the guest user profiles have access to these apex classes assigned at the profile level so how are these profiles even able to see those classes?
  2. The wording suggests that not having access is actually a problem:

AuraEnabled Apex Classes: The report will highlight any class with potential risks that is:

1) AuraEnabled or maybe AuraEnabled (If part of a managed package and the report cannot read the code within the class)

2) If the Guest User Profile does not have access to the class

To me, this is the opposite of a problem, we don't want guest users to have access to the class so why are these flagged as potential risks? 

 

Unfortunately an article was published and caught the eye of our leadership, I can't provide them a report with 10,000 potential risks that may not actually be risks.

3 respostas
  1. 28 de abr. de 2023, 20:40

    Thanks @Admin User - only challenge there is that the User Access Report can actually be run for guest, external, and internal users...so it's not always a site url to run the report (like in the case of internal users). But I will give it some thought on how to incorporate.

     

    Thanks again!

0/9000