Member Junction
    Preparing search index...
    • FLS22 — the audit trail is FLS-projected against the entity each row is ABOUT.

      This is the leak the guide previously documented as a trust boundary administrators had to configure around: MJ: Record Changes has field security switched OFF (it is not the entity being secured), so every other enforcement point short-circuits and the row's payload carries the old and new values of a denied column in plain text. Anyone with entity read on the audit trail could read a denied Email straight out of it.

      The reader is denied Email on MJ: Employees (FLS3), and holds entity read on Record Changes (seeded). The writer is denied nothing, and is the control: the same rows must reach it whole, so this proves projection rather than blanket suppression.

      Returns Promise<void>