{"id":1249,"date":"2020-02-18T09:34:27","date_gmt":"2020-02-18T09:34:27","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/anonymouscreateobject\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"anonymouscreateobject","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/anonymouscreateobject","title":{"rendered":"Anonymous users should only be allowed to create non-persistent entities"},"content":{"rendered":"\n<p> Released in version 1.6 (03 March 2020) <\/p>\n\n\n\n<p>Otherwise, a malicious agent could create millions of objects causing the database to run out of space. Note that XPath constraints are not applied when creating new objects.<\/p>\n\n\n\n<p><strong>Non-compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"784\" height=\"300\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-14.png\" alt=\"\" class=\"wp-image-1251\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-14.png 784w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-14-480x184.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 784px, 100vw\" \/><\/figure>\n\n\n\n<p>*assuming that <em>AnonymousUserModuleRole<\/em> is a module role that is related to the project role for anonymous users in the app.<\/p>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<p>No create access or the entity should be non-persistable.<\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":1,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-1249","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1249"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1249"}],"version-history":[{"count":3,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1249\/revisions"}],"predecessor-version":[{"id":1255,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1249\/revisions\/1255"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"A project administrator should only be able to create administrative accounts","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityprojectadminslimitmodules","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1483"}],"prev":[{"title":"Access rules in multi-tenant apps should lead to CurrentUser","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/accespathuser","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/237"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1249"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=1249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}