Skip to main content

#Security Review2 discutindo

Hi everyone,

We are preparing an external API / web application integration for our AppExchange Security Review. The review team will need to test our API endpoints from their automated scanning suites and dynamic networks.

Our main operational blocker right now is MFA and Device Activation (OTP). Because our team does not have personnel available on standby 24/7 to instantly provide multi-factor authentication access codes or email OTP tokens to the reviewers, we need an entirely hands-off authentication architecture for our test environment.

Given Salesforce’s strict platform enforcements restricting traditional UI MFA bypass permissions, what is the current accepted practice for API apps?

My Questions:

  • If we provision a dedicated Salesforce Integration User license (which uses API-only tokens/OAuth instead of interactive UI login), does the Security Review team's automated testing suite natively support this without triggering an MFA or Device Activation challenge?
  • If the review suite requires standard user credentials that trigger an unexpected email OTP, how are partners managing this asynchronously without a 24/7 live operations team to hand over codes?

We want to make sure we architect our authentication flow correctly so that the submission doesn't fail pre-queue validation due to a missed MFA prompt. Any advice from recent submitters would be huge. 

 

#Appexchage Apps

 

 

#Security Review  #Agentforce

1 resposta
  1. 22 de set., 05:44

    For an AppExchange Security Review, I’d avoid designing around the assumption that an API-only user automatically bypasses every authentication control. The safer approach is to confirm the current review-team requirements for integration credentials and test the exact OAuth/API flow in the submitted environment beforehand. If automated scanners require interactive authentication, Salesforce Partner Support or the Security Review team should clarify the supported testing arrangement rather than relying on manual OTP handling.  Visit here for more information.

0/9000

Hi Everyone,

We’re currently facing challenges with the AppExchange security review process for our managed package. The application integrates Salesforce with an external Node.js-based web application.

While we’ve addressed most issues within the Salesforce managed package, previous security reviews have flagged concerns with the external web application. We’re looking for guidance or expert assistance from someone familiar with navigating Salesforce security reviews, particularly in scenarios involving external web applications.

If you know of any professionals who can help, please share their contact information or point us in the right direction.

Any help or advice would be greatly appreciated. Thank you!

 

#AppExchange  #Security Review  #External Application  #Integration  #Hiring

0/9000

 value="{!v.singleRec.Name}" /> 

<span class="slds-truncate" title="Name">{!v.singleRec.Name}</span> 

 

This is the code for the aura component. I am receiving a Client DOM XSS vulnerability in the Checkmarx report of the Force.com source code scanner for the security review. I am unable to identify the precise problem.

 

#TrailblazerCommunity  #Trailhead  #Security Review

1 comentário
0/9000

I am having custom profile , I have assigned it to user , however after assigning all types of permission set and object setting to view and modify all for return order object. Return order owd is private #Security Review #Security #FSL Mobile

2 respostas
  1. 30 de mai. de 2024, 13:48

    In a Profile or Permission Set make sure to check the "Use Order Management Return Order" system permission to be able to access Return Order Object.

     

    This is a poorly documented behavior of Return Order object that is counter-intuitive to troubleshoot as without this permission OWD and CRUD settings are ignored.

     

    Hope this helps!

0/9000

Hi - My app has recently failed a security review. I'm comfortable that I can make the required changes but I wondered if anyone knew how long Salesforce typically took to complete their second review once I've resubmitted?

1 resposta
  1. Ines Garcia (get: Agile) Forum Ambassador
    12 de out. de 2023, 11:10

    It varies quite a bit depending on how many changes you have to make and the workload of the team.

    Assuming you are registered as ISV you can tap into your allocated PAM via the partner portal

0/9000

Hey all, 

 

I am facing an issue while trying to submit security review for a package in salesforce.

ERROR: "Error occurred while loading a Visualforce page" at http://partners.salesforce.com at listing of security review stage. Please guide me a way how to proceed further.

4 comentários
  1. 25 de jan. de 2023, 20:26

    Alright, figured out the issue.  Salesforce needs to approve the listing before you can send for review.  You need to submit your business plan and a Salesforce rep will contact you.  Apparently the Visualforce page will break without the approval.

     

    ***Leaving for other folks that might hit the same issue***

0/9000

Back when the whole Guest User Security thing started, I ran into an issue with queries to certain setup objects from Guest Users.  The metadata reported that the objects where inaccessible when should be.  In order to work around that issue, I have one class that is declared without sharing that does not do CRUD/FLS checks.  This class queries Group, GroupMember, UserRole, and OrgWideEmailAddress.

 

Anyone know if that issue has been fixed? 

 

We're about to go through security review and if the issue is fixed, I can change the class declaration and add WITH SECURITY_ENFORCED to the queries.  If the issue is not fixed, I'll have to document it as a false positive.

1 comentário
  1. 20 de mai. de 2021, 22:01
    These are considered "setup" objects, which we don't want to be accessed by a guest user. So you will have to continue doing this in a without sharing class, but the AppExchange security team should be aware of this pattern. If you have any issues with reviews there please post back here and we can help with alignment.
0/9000

Hi, 

In the new design for security review updating the Billing information one every new release started to be a strange behaviour for us also the stringiest part it ask us for the address information not for card information, Is there away we can save the information?

0/9000

@SecurityForce 

 

We have developed one custom Salesforce app and before we submit for Salesforce security review, it would be good to have your feedback on below question.

 

As part of this app, we are fetching data using API from 3rd party website and storing some information on custom object in Salesforce and displaying information real time based on user selecting on Salesforce.

 

We have already scanned Salesforce app using Checkmarx: https://security.secure.force.com/security/tools/forcecom/scanner and worked on points, as identified and suggested by scanner.

 

Do we need to scan, 3rd party website using Chimera Scanner as per this page https://security.secure.force.com/sourcescanner/ ? As I mentioned above, we use this website for API calls and fetching data to be displayed on Salesforce app.

 

Looking forward to your feedback!

 

Thank you,

Brijesh

2 comentários
0/9000

Hi. I am about ready to submit our app for security review. I am curious if Salesforce offers any voucher or discount to reduce the listing fees  ($2700) for small business affected due to COVID slow down. Thanks!

0/9000