{"id":594,"date":"2019-12-09T11:04:45","date_gmt":"2019-12-09T11:04:45","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/microflows-that-should-not-have-permissions\/"},"modified":"2022-04-14T08:25:21","modified_gmt":"2022-04-14T08:25:21","slug":"microflowunneccesarypermissions","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/microflowunneccesarypermissions","title":{"rendered":"Microflow should only have permissions if used from a page"},"content":{"rendered":"\n<p style=\"text-align:center\">Introduced in version: 1.3 (29 Jan 2020)<\/p>\n\n\n\n<p>Microflows that are used as sub-microflows and microflows that are used for unit tests are examples of microflows that do not need and should not have permissions.<\/p>\n\n\n\n<p><strong>Non-compliant example:<\/strong><\/p>\n\n\n\n<p>Assuming that the microflow is only used as a sub-microflow: <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"774\" height=\"442\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-41.png\" alt=\"\" class=\"wp-image-945\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-41.png 774w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-41-480x274.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 774px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<p>Assuming that the microflow is only used as a sub-microflow:<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-40.png\" alt=\"\" class=\"wp-image-944\" width=\"538\" height=\"300\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-40.png 538w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/01\/image-40-480x268.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 538px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>How to solve this violation?<\/strong><\/p>\n\n\n\n<p>When you are working on solving this violation, but you get a message in Studio Pro that states that the specific microflow does need permission, make sure that you have applied the correct naming convention:<br><br>&#8211; If the microflow is used directly from a page, the microflow should not start with <em>SUB<\/em>. Read through our <a href=\"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/project-hygiene\" target=\"_blank\" rel=\"noreferrer noopener\">documentation<\/a> to select the correct naming convention for the function of your microflow. If you use the microflow both from a page and as a sub-microflow somewhere else in the project, we advise creating a microflow that calls the sub-microflow, and that you handle the permission there.<br><br>&#8211; If a sub-microflow is also called from a nanoflow, we recommend using a special <strong>Nsub_ <\/strong>wrapper (with permissions) in the nanoflow that calls the SUB_microflow (with no permission) that is also used as a regular sub-microflow. Read more about this naming convention <a href=\"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/project-hygiene\/microflowprojecthygienesubinnanoflow\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<br><br>&#8211; If the specific microflow is used from the project navigation, we recommend changing the prefix to <strong>Nav_<\/strong>. Read more about this naming convention <a href=\"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/project-hygiene\/projecthygieneprojectmicroflownavigation\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":22,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-594","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/594"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=594"}],"version-history":[{"count":11,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/594\/revisions"}],"predecessor-version":[{"id":2453,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/594\/revisions\/2453"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Published Rest and Web services should require authentication","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/publishedserviceauthentication","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1369"}],"prev":[{"title":"Microflow called from the client should apply entity access rules","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/microflowentityaccess","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/249"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=594"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}