{"id":243,"date":"2019-11-01T13:46:08","date_gmt":"2019-11-01T13:46:08","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/security-level-production\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"securitylevel","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securitylevel","title":{"rendered":"Security should be enabled and set to Production"},"content":{"rendered":"\n<p>Security should be considered from the start of a project. Keeping security disabled until the project is close to release will often lead to &#8220;generous&#8221; access for users as developers try to get rid of all mendix access errors as fast as possible without too much thought.<br>With this security level, developers are asked to consider security from the get-go which leads to stricter access rules.<\/p>\n\n\n\n<p><strong>Noncompliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-31.png\" alt=\"\" class=\"wp-image-922\" width=\"566\" height=\"99\"\/><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"993\" height=\"230\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-32.png\" alt=\"\" class=\"wp-image-923\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-32.png 993w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-32-980x227.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-32-480x111.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 993px, 100vw\" \/><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":14,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-243","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/243"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=243"}],"version-history":[{"count":4,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/243\/revisions"}],"predecessor-version":[{"id":924,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/243\/revisions\/924"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Unlimited string attributes should not be editable by anonymous users","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/anonymousunlimitedstring","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1254"}],"prev":[{"title":"Retracted Mendix versions should not be used","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/retractedmendixversion","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1216"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=243"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}