{"id":2162,"date":"2021-07-30T09:00:48","date_gmt":"2021-07-30T09:00:48","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/attribute-widgets-in-data-views-should-be-editable\/"},"modified":"2021-08-18T08:30:15","modified_gmt":"2021-08-18T08:30:15","slug":"pagesecuritydataviewattributeseditable","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/pagesecuritydataviewattributeseditable","title":{"rendered":"Attribute widgets in data views should be editable"},"content":{"rendered":"\n<p id=\"block-65feb11c-fc9e-472a-822a-29fbdc9f4864\">Introduced in version 2.6 (released August 2021)<\/p>\n\n\n\n<p>Keep your attributes editable within data views, because if an access rule prohibits write access, your client will display it as non-editable \u2013 this way you are aware of the (correct) working of an access rule.<\/p>\n\n\n\n<p><strong>Why is it a security risk?<\/strong> <br>Whilst testing your application, it may be more difficult to spot if your security is managed the right way due to the fact that it may seem that a user has no access to an attribute (editability managed on the page: never) whilst the security is wide open in the domain model. Therefore it\u2019s good practice to always set the editability of an attribute reference widget to default.<\/p>\n\n\n\n<p><strong>Non-compliant example<\/strong><br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"107\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-2-1024x107.png\" alt=\"\" class=\"wp-image-2168\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-2-980x102.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-2-480x50.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><figcaption>The editable value is set to <em>Never<\/em>. We do not recommand this practice.<\/figcaption><\/figure><\/div>\n\n\n\n<p><strong>Compliant example<\/strong><br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"104\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-3-1024x104.png\" alt=\"\" class=\"wp-image-2169\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-3-980x100.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-3-480x49.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><figcaption>The editable value is set to <em>Default<\/em>.<\/figcaption><\/figure><\/div>\n\n\n\n<p><strong>How to solve?<\/strong><\/p>\n\n\n\n<p>Set the <em>editable<\/em> value in the properties menu to <em>Default<\/em>.<br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"412\" height=\"657\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image.png\" alt=\"\" class=\"wp-image-2172\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image.png 412w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-188x300.png 188w\" sizes=\"(max-width: 412px) 100vw, 412px\" \/><\/figure><\/div>\n\n\n\n<p>In some cases, the attribute reference that is violated is part of an inherited editability. This is caused by setting a (e.g.) data view or list view to not-editable. As a consequence, all the nested widgets inherited the set editabilty. This is shown in the modeler as:<br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"91\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-2-1024x91.png\" alt=\"\" class=\"wp-image-2174\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-2-980x87.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-2-480x43.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure><\/div>\n\n\n\n<p>If the attribute widget without inheritance is set to <em>never<\/em>, the rule will give a violation. To fix this violation, go to the top level widget that causes the inherited editability, change it (temporarily) from no to <em>yes<\/em>. Go to the violated widget and set its editable value to <em>default<\/em>. If correct, change the editability of the top widget back to <em>no<\/em>.<br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"287\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-3-1024x287.png\" alt=\"\" class=\"wp-image-2175\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-3-980x275.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/08\/image-3-480x135.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure><\/div>\n","protected":false},"featured_media":0,"parent":96,"menu_order":19,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2162","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2162"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2162"}],"version-history":[{"count":5,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2162\/revisions"}],"predecessor-version":[{"id":2178,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2162\/revisions\/2178"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Entity access should be applied when generating documents","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/generatedocumentaccess","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1242"}],"prev":[{"title":"Always use the inherited entity to create records for System.FileDocument or System.Image","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityavoidsystemfiledocument","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2129"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2162"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=2162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}