{"id":1473,"date":"2020-05-06T12:24:18","date_gmt":"2020-05-06T12:24:18","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/entity-access-default-rights-for-new-members-should-be-none-or-read\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"securityentitydefaultmemberaccess","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityentitydefaultmemberaccess","title":{"rendered":"Entity access default rights for new members should be None or Read"},"content":{"rendered":"\n<p> Introduced in version 1.10 (May 2020) <\/p>\n\n\n\n<p>Entity\naccess default rights for new members should be None or Read. This forces you\nto think about each attribute that is added to an entity and prevents unwanted\naccess by mistake. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"604\" height=\"274\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/05\/tmp1.png\" alt=\"\" class=\"wp-image-1475\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/05\/tmp1.png 604w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/05\/tmp1-480x218.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 604px, 100vw\" \/><\/figure>\n\n\n\n<p>You can\nconfigure to skip entities that belong to certain debug or developer user roles,\nso those user roles are allowed to have read-write by default.<\/p>\n\n\n\n<p>Optionally\none can choose to only allow only None. This is even more secure, but might be\ntoo strict for some.<\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":6,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-1473","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1473"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1473"}],"version-history":[{"count":3,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1473\/revisions"}],"predecessor-version":[{"id":1479,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1473\/revisions\/1479"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Entity access rules should be using attributes\/associations with at most read access in XPath constraints","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityentityaccessxpath","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2041"}],"prev":[{"title":"Demo users should be turned off","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/nodemousers","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/506"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1473"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=1473"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}