Announcement

Collapse

Information Needed

See more
See less

Secure Guest Users’ Sharing Settings and Record Access

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Secure Guest Users’ Sharing Settings and Record Access

    I am working through the Salesforce Security Alerts concerning the security changes/best practices around the guest user profiles.

    I am seeing that our Org has a Click and Pledge site (and therefore a guest user). I am also seeing that the CnP guest user has external access to contacts and accounts. I am trying to get more information on the permissions and setup needed for ClickNPledge. I am also seeing that we have some CnP objects with external access enabled (org wide defaults). I am beginning to think that the security changes being pushed by Salesforce may have an impact with CnP integration.

    I am preparing to test these changes in sandbox (along with a lot of other changes) and some of the instructions provided by Salesforce documentation seems to suggest that some of the setting changes may be irrevocable. In other words, once you turn it on, you have to go with it. see https://help.salesforce.com/articleV...ing.htm&type=5

    Do you have any recommendations for maintaining proper CnP functioning given the changes to Salesforce guest user security? Do you have documentation on what obj access is required for site guest users? Can I activate "Secure guest user record access" setting without impacting CnP functionality?

    Thanks!
    -Soren Paris (ASLE)

  • #2
    Good day @sorenparis

    Our recommendations for maintaining proper functioning concerning the Site Guest User is to make sure that the Site Guest User is using the "PS-CnP-Event-ONLY-SiteGuestUser" permission set. Also, any additional Contact Custom Fields that have been added to the Form fields in Event Management needs to be available to the Site User to function correctly.

    Regarding the security change that Salesforce has announced recently, we believe you are referring to the "Secure guest user record access" being checked. We have reviewed this potential change and tested it thoroughly. As long as the correct permissions we describe above are in place, we do not expect any impact on how our Salesforce apps function.

    Click image for larger version

Name:	other settings.jpg
Views:	28
Size:	25.3 KB
ID:	49894

    Of course, I'm sure you realize that with the Salesforce platform, there are many, many variations potentially available, so should you encounter any issue that you believe may be caused by this change, we would encourage you to let us know so that we may address it as soon as possible.
    Regards,
    Click & Pledge Support Department

    On Salesforce? Help us by rating our app: Click & Pledge Donor Management on AppExchange

    Join us @ the educational webinars: https://clickandpledge.com/webinars/
    Live Support available Join between 3:00 - 3:30 p.m. ET Monday - Thursday: https://clickandpledge.com/webinars/
    Are you on Salesforce? Join us at the Power of Us Hub: https://powerofus.force.com/0F980000000CjpC

    Comment


    • #3
      Thank you. This is helpful.

      I reviewed the site guest user for C&P Default Site.

      I see that the associated user has 2 permission sets assigned.
      "PS-CnP-Event-ONLY-SiteGuestUser"
      "PS-CnP-PaaS-ONLY-SiteGuestUser"

      The site user also has the profile, and if I understand you, the access provided by the profile is only required for any additional custom fields not already covered by the permission set. Is that correct?

      I will continue to implement these changes and test them in sandbox.

      Thanks!
      -Soren

      Comment


      • #4
        That is correct. Any custom fields are not included in the permissions sets.
        Regards,
        Click & Pledge Support Department

        On Salesforce? Help us by rating our app: Click & Pledge Donor Management on AppExchange

        Join us @ the educational webinars: https://clickandpledge.com/webinars/
        Live Support available Join between 3:00 - 3:30 p.m. ET Monday - Thursday: https://clickandpledge.com/webinars/
        Are you on Salesforce? Join us at the Power of Us Hub: https://powerofus.force.com/0F980000000CjpC

        Comment

        Working...
        X