Completely Hide or Fall back view when on browser

Greetings everyone,

 

Im have this issue of security on my head. We  know that whenever a User is on browser, He can access other hidden view if link is being share by other user. With this, Is there any future plans to completely disable view if user dont have access with that? Or is there a kind of fall back view whenever user access the hidden view? 

Any thoughts or workaround everyone? Note : Security filters wont do the job as I needed some of the rows for other set up. 

 

Thank you, Hope you understand what I mean

0 4 163
4 REPLIES 4


@AngeloParana wrote:

Thank you, Hope you understand what I mean


You mean the URL parameters? So there are views that are hidden for some users but they still can see if they enter to those views directly using the URL parameter? I haven't tested but this should not be the case. In case it's doing it, please report this to support.

An alternative would be to use show_if on each column to also hide those if needed so that even if the view can be opened the fields are not there, but I can see how cumbersome this would end

If you can elaborate on your situation, someone can perhaps suggest a solution here. Not really sure how to respond to that generic question, except that I doubt there is any plan to change anything there. You mean that certain records need to be available for other functionality, but the user shouldn't see them? As Oscar suggested, perhaps specific per column show_if expressions would be in order here.

 


@SkrOYC wrote:

So there are views that are hidden for some users but they still can see if they enter to those views directly using the URL parameter? I haven't tested but this should not be the case. In case it's doing it, please report this to support.


Yes that is what I also understand that he means. But no I don't agree with "this should not be the case", this is how it has always been.

 


@Marc_Dillon wrote:

this is how it has always been


Sure, I understand, but it's a security risk that should be fixed I think.
I recall that we have been remembered that Security Filters is the only way to prevent users from getting unwated data, so that Slices or Hidden Views are not a secure mechanism to hide crucial information from our users, but still think that this could be upgraded to prevent manipulation in the URL to go to a view that's not meant for the user

 

IMG_20221020_221537.jpg

Hello @Marc_Dillon & @SkrOYC  suppose that this X view is can be see/clickable by this user1 and other user cant see it. 

Now whenever user 1 go to the X view and copy the link on the browser then share it to other user, Other user can now see that view even it was hidden from him.

From the word itself "Show if"  it just hide  the view (when conditions are not met)  but not totally removing the access. It is ok on mobile app since there was no other way to direct access the view unless you expose certain button to link the view. But its different on the browser since it has URL bar.

Wrapping link to iFrame is a good workaround but it will only work on Public app. I hope it will be possible. 

Top Labels in this Space