SalesforceSalesforce DeveloperSecurity and AccessMedium
Apex runs in system context by default. How do you make sure your code respects the running user's permissions?
Suggested answer
For record access, I declare classes with sharing unless there is a documented reason not to. For object and field permissions, I use user mode database operations, such as WITH USER_MODE in SOQL and AccessLevel.USER_MODE for DML, or Security.stripInaccessible to remove fields the user cannot access.
I also review code in security scans and write tests that run as users with limited permissions using System.runAs.
What interviewers look for
The interviewer looks for a clear distinction between sharing (records) and CRUD/FLS (objects and fields), plus current enforcement techniques. A pitfall is believing that with sharing also enforces field-level security.
Original practice content; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.