{"id":239,"date":"2019-11-01T13:45:16","date_gmt":"2019-11-01T13:45:16","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/apply-entity-access-on-entities\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"accessnoxpath","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/accessnoxpath","title":{"rendered":"Access rules in multi-tenant apps should have an XPath constraint"},"content":{"rendered":"\n<table class=\"wp-block-table\"><tbody><tr><td>\n  Check if these roles have entity access\n  <\/td><\/tr><tr><td>\n  For multi-tenant apps it is important\n  that users can only see their own data. The previous rule (Access rules\n  leading to a user) require a certain multi tentant setup. This rule is weaker\n  and requires only any xPath on the entity accessed by a certain role.\n  <\/td><\/tr><tr><td>\n  Add a comma separated numeration of roles\n  for which this rule applies.\n  <\/td><\/tr><\/tbody><\/table>\n","protected":false},"featured_media":0,"parent":96,"menu_order":17,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-239","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/239"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=239"}],"version-history":[{"count":4,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/239\/revisions"}],"predecessor-version":[{"id":831,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/239\/revisions\/831"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Always use the inherited entity to create records for System.FileDocument or System.Image","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityavoidsystemfiledocument","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2129"}],"prev":[{"title":"User roles with a certain amount of module roles should be checked for security","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/checksecurityrole","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/500"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=239"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}