Skip to main content

#New Releases

https://help.salesforce.com/articleView?id=release-notes.rn_lc_oauth_ru.htm&type=5&release=232

 

This update enforces the scope of an OAuth token used to authenticate a Lightning app. The scope of an OAuth token is defined in a connected app. This change prevents a Lightning app from using OAuth tokens with unintended permissions. This update is scheduled for enforcement in Winter ’22.

 

How to test this update weather it is impacting my org or not ?

1 个回答
  1. 9月20日 13:35

    Hi Raj, you can check this from Setup → Release Updates and look for “Enforce OAuth Scope for Lightning Apps.”

    To test whether your org is impacted:

    1. Test the release update in a sandbox first.
    2. Open the release update and click View Details / Get Started.
    3. Test any Lightning or Lightning Out apps that use OAuth authentication.
    4. Check Setup → Login History for OAuth logins where Login Type = Remote Access 2.0 and review the Application column for the connected app being used.
    5. Cross-reference those logins in Session Management, particularly sessions with Session Type = Aura.
    6. Review the OAuth scopes configured on the relevant Connected Apps. The scope should provide the access required by the Lightning app, such as lightning, visualforce, web, or full when necessary.

    Salesforce specifically recommends testing Lightning and Lightning Out applications in a sandbox before enabling/enforcing the update. 

0/9000