How do you enforce sharing, object, and field security in Apex, and where do developers most often get this wrong?
Suggested answer
The single most common mistake is believing that with sharing covers everything. It does not — it enforces record-level sharing only. Object CRUD and field-level security are entirely separate and must be enforced explicitly.
The tools I would expect a developer to use:
1. Sharing keywords: with sharing, without sharing, and inherited sharing, which takes the caller's context and is the right default for a reusable service class.
2. User-mode operations: WITH USER_MODE in SOQL, and AccessLevel.USER_MODE with Database.query and DML, which apply CRUD, FLS, and sharing together.
3. Security.stripInaccessible(): Removes fields the user cannot access from a result set or an inbound payload, without throwing.
4. WITH SECURITY_ENFORCED: Throws when an inaccessible field is referenced — appropriate when you want to fail loudly.
5. Describe checks such as isAccessible() and isUpdateable() for conditional logic.
The second common mistake is Visualforce and Aura controllers: pages on a standard controller enforce sharing, CRUD, and FLS, but a custom controller runs in system context until the developer says otherwise.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.