{"id":249,"date":"2019-11-01T13:55:27","date_gmt":"2019-11-01T13:55:27","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/apply-entity-access-on-flows\/"},"modified":"2022-04-14T08:19:14","modified_gmt":"2022-04-14T08:19:14","slug":"microflowentityaccess","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/microflowentityaccess","title":{"rendered":"Microflow called from the client should apply entity access rules"},"content":{"rendered":"\n<p>For multi-tenant apps, it is important that users can only see their own data. The rule <a href=\"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/accessnoxpath\">\u2018Access rules leading to a user\u2019<\/a> requires proper domain model access rules configuration. <\/p>\n\n\n\n<p>This rule requires that all microflows available to <strong>tenant <\/strong>users have entity access turned on. This makes sure there is no accidental data leakage via strings, messages or non-persistent entities. <\/p>\n\n\n\n<p>A list of tenant user roles can be configured  for which this rule should be applied, e.g. &#8220;<em>TenantUser,TenantAdministrator<\/em>&#8221; <\/p>\n\n\n\n<p>This rule is in contradiction to <a href=\"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/performance\/microflowentityaccess\">Microflow should not apply entity access<\/a>. When developing multi-tenant apps, our advice is to apply entity access. The performance hit is preferred to potential data breaches.<\/p>\n\n\n\n<p><strong>Noncompliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-37.png\" alt=\"\" class=\"wp-image-938\" width=\"556\" height=\"307\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-37.png 556w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-37-480x265.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 556px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-39.png\" alt=\"\" class=\"wp-image-940\" width=\"559\" height=\"314\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-39.png 559w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-39-480x270.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 559px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Configuration:<\/strong><\/p>\n\n\n\n<p>If you want to enable this rule, go to its Rule Settings, enable the rule and add the role(s) that need entity access if used from the client.<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"996\" height=\"531\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image.png\" alt=\"\" class=\"wp-image-2142\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image.png 996w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-980x522.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/07\/image-480x256.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 996px, 100vw\" \/><\/figure>\n","protected":false},"featured_media":0,"parent":96,"menu_order":21,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-249","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/249"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=249"}],"version-history":[{"count":11,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/249\/revisions"}],"predecessor-version":[{"id":2451,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/249\/revisions\/2451"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Microflow should only have permissions if used from a page","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/microflowunneccesarypermissions","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/594"}],"prev":[{"title":"Entity access should be applied when generating documents","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/generatedocumentaccess","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1242"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=249"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}