Data Policies save the day
Luckily, Chapter 2, Developing Custom Applications, showed you a way to protect against such an attack. We've already put a Data Policy in place that captures the error. The familiar red error message is displayed, and the record is not committed to the database. We've been saved by the server-side check. If you wish, try disabling the Data Policy to prove that this is the only thing that is stopping the error from being shown.
This scenario is possible regardless of your role in the instance. You do not need to be an admin to disable mandatory fields in this way. With the right knowledge, a malicious user can instruct the browser to change the status of fields, setting read-only fields to writeable or mandatory ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access