{"id":500,"date":"2019-11-15T15:09:54","date_gmt":"2019-11-15T15:09:54","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/project-role-checked\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"checksecurityrole","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/checksecurityrole","title":{"rendered":"User roles with a certain amount of module roles should be checked for security"},"content":{"rendered":"\n<p>Security should be checked for each project role. This guarantees that roles have access to the data that they require. When enabled from the start of the project this leads to strict access rules that give users access to the minimum set of data needed to pass the security check.<\/p>\n\n\n\n<p>For convenience, it is possible to configure this rule to only violate once a project role has more than N module roles. In exceptional cases some project roles, for example, a &#8216;Debug&#8217; role or a web service role can be excluded from this check by whitelisting the violation.<\/p>\n\n\n\n<p><strong>Noncompliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"735\" height=\"786\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-36.png\" alt=\"\" class=\"wp-image-933\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-36.png 735w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-36-480x513.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 735px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"558\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-35-1024x558.png\" alt=\"\" class=\"wp-image-932\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-35-980x534.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-35-480x261.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n","protected":false},"featured_media":0,"parent":96,"menu_order":16,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-500","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/500"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=500"}],"version-history":[{"count":5,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/500\/revisions"}],"predecessor-version":[{"id":935,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/500\/revisions\/935"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Access rules in multi-tenant apps should have an XPath constraint","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/accessnoxpath","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/239"}],"prev":[{"title":"Unlimited string attributes should not be editable by anonymous users","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/anonymousunlimitedstring","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1254"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=500"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=500"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}