Security
The browser of the user who is loading the page and requesting the content is the literal client that's performing the action, and running any Client Scripts, UI scripts, client-side UI actions, processing the UI policies and applying UI policy actions. This includes controlling whether fields are mandatory, read-only, or indeed - visible at all.
This can seem like an effective means of protecting content; for example, by hiding a field if the user doesn't have the appropriate roles. However, it's important to realize that any client-side measures can be overridden by the user. For anything which really, needs to be secured from the user seeing or modifying them, should be secured using ACLs (security rules).
Data policies are another ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access