9.6119.0 - Related data field for dynamic content type - no

Posted by Community Admin on 04-Aug-2018 16:09

9.6119.0 - Related data field for dynamic content type - no security trimming

All Replies

Posted by Community Admin on 20-Sep-2016 00:00

When I create a content type and restrict its permissions (view, create, etc) to a certain role, or set of roles, users not in those roles can still see all of them. Also,  since the related data field is pulling from an api, this seems like a bad security hole. There's nothing preventing users from making those api calls themselves.

This thread is closed