feed-icon-32x32.png

Demand Tools by CRM Fusion

Learn how Salesforce.com can help your business
arrowpointe @ twitter
  • New blog post: Getting Standard Object Meta Data into the Force.com IDE http://tinyurl.com/62xsqu 1 week ago
  • I think Facebook went down. anyone else getting that? 1 week ago
  • perceived delays in getting the Lucid Era trial started were due to my misunderstanding of the product. my bad. 1 week ago
  • Lucid Era sure makes it hard to get a trial started with their Salesforce product 1 week ago
  • nevermind. i misread the instructions :) 1 week ago
  • has anyone been able to complete "Synchronizing with your Force.com Developer Edition org" at http://snipr.com/2nspq 1 week ago
  • jungle disk upgrade went smoothly. in terms of "bang for the buck", Jungle Disk is a top-notch app (snag-it is another) 1 week ago
  • More updates...

Powered by Twitter Tools.



API Authentication List

I submitted an entry on IdeaExchange today about adding more authentication to the API to avoid rogue applications/people from wreaking havoc in your system and to provide a means of tracking the applications that modify your data.

Someone with average programming skills could cause some destruction via the API if they wanted to and I think some mechanism of locking it down further would be good. Also, since so many applications will be accessing/manipulating data via the API, it’d be good to limit what an app can do (e.g. only access specific objects, read vs. write) and also to track the application that is making changes to records. It’s like having application-specific profiles. When a user logs into Salesforce via a external application, they only get the permissions where their user profile and the application’s profile match (maybe they have delete Account rights in their user profile, but the application profile doesn’t allow deletes. They won’t be able to delete Accounts when using that application).

I don’t have the design all figured out, but it’s the idea I wanted to get across. I am interested in what you all think. If you have an opinion (agree or disagree), please add your comments to the post on IdeaExchange.

http://ideas.salesforce.com/article/show/42227/API_Authentication_List

Leave a Comment

All comments are moderated. Other visitors will not see your comment until it has been approved.