{"id":1242,"date":"2020-02-18T08:48:49","date_gmt":"2020-02-18T08:48:49","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/generatedocumentaccess\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"generatedocumentaccess","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/generatedocumentaccess","title":{"rendered":"Entity access should be applied when generating documents"},"content":{"rendered":"\n<p> Released in version 1.6 (03 March 2020) <\/p>\n\n\n\n<p>This is a potential security issue. If entity access is not applied in a microflow that generates a document a user could see data that they are otherwise not allowed to access.<\/p>\n\n\n\n<p><strong>Non-compliant example:<\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"715\" height=\"493\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-13.png\" alt=\"\" class=\"wp-image-1247\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-13.png 715w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-13-480x331.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 715px, 100vw\" \/><\/figure><\/div>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-12.png\" alt=\"\" class=\"wp-image-1246\" width=\"440\" height=\"185\"\/><\/figure><\/div>\n","protected":false},"featured_media":0,"parent":96,"menu_order":20,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-1242","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1242"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1242"}],"version-history":[{"count":2,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1242\/revisions"}],"predecessor-version":[{"id":1248,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1242\/revisions\/1248"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Microflow called from the client should apply entity access rules","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/microflowentityaccess","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/249"}],"prev":[{"title":"Attribute widgets in data views should be editable","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/pagesecuritydataviewattributeseditable","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2162"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1242"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=1242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}