Hi everyone,
I've created a workflow that attaches a URL to the send email action.
The URL calls a Suitelet that updates the customer records mailing preferences.
But, is the URL opening my system up to attack or vulnerabilities by sending this out?
As far as I imagine, the most they could do is update the mailing preferences of my customers if they also know the various entityid's
https://*******-sb1.extforms.netsuite.com/app/site/hosting/scriptlet.nl?script=4511&deploy=1&compid=*******_SB1&ns-at=AAEJ7tMQusG5Rp*******MxnXSt-inLt-KendSDFYrep-TYvCSo&custom_entityid=TEV2079
I've intentionally hidden my system number and part of the ns-at token from the deployment record used in the URL, but I'm sure you get the idea.