Role-based Security on BO doesn't seem to work
Summary: I am trying to setup Role-based Security on my Business Object (based on a table in ATP).
I went to "Authenticated Users, and for VIEW rights added a clause. On a side note, it doesn't allow me to select the default "Allow if user created the row"
But during the app run, the security is not enforced. Further this means user can easily manipulate the json payload, replay the call and get all the data.
In addition to this, there doesn't seem to be any option to add a Groovy Script based complex logic in this area, or does VBCS offers any sort of session-state-protection like adding checksums (similar to APEX)?
Tagged:
0