Skip to main content

Code reviews rule: OmniStudio component without a required permission

Written by David Martin

OmniStudio component without a required permission

Why is this an issue?

Required Permission decides who may use a component. Leave it blank and every user who can reach the component can use it, whether or not they were meant to.

It matters most on Data Mappers and Integration Procedures, because those can be run directly — over the OmniStudio REST endpoints, from Apex, or as an action of another component — so no user interface stands between a user and the data behind them. On FlexCards it is narrower: it controls whether the card renders for a user, not access to the data it shows, which stays governed by field-level security.

This rule applies only to Data Mappers (OmniDataTransform, formerly DataRaptor), Integration Procedures, and FlexCards / OmniUI and Vlocity Cards. OmniScripts are out of scope, because they have no Required Permission property to set and reach data only through the components they call. Inactive components are skipped, since they cannot run.

Examples

In OmniStudio metadata the permission lives in the component's propertySetConfig JSON, XML-escaped in storage and shown decoded here. On Integration Procedures it may instead sit in a sibling <requiredPermission> element; either location counts.

Example of incorrect code — the field is absent, empty, or only whitespace:

<OmniUiCard>
<propertySetConfig>{ "isFlex": true, "requiredPermission": "", ... }</propertySetConfig>
</OmniUiCard>

Example of correct code:

<OmniUiCard>
<propertySetConfig>{ "isFlex": true, "requiredPermission": "Account_Manager", ... }</propertySetConfig>
</OmniUiCard>

In Vlocity DataPacks it is a top-level field, namespaced in classic packs (%vlocity_namespace%__RequiredPermission__c) and plain in OmniStudio-format ones (RequiredPermission). Any field whose name contains RequiredPermission counts, so long as its value is not empty or whitespace.

Incorrect:

{ "%vlocity_namespace%__RequiredPermission__c": "" }

Correct:

{ "%vlocity_namespace%__RequiredPermission__c": "Account_Manager" }

How can I fix violations?

Set Required Permission in the designer to the least-privileged permission that still lets the intended users work:

  • On a Data Mapper or Integration Procedure, a role, profile, permission set, or custom permission.

  • On a FlexCard, a comma-separated list of custom permissions, created first under Setup > Custom Permissions.

In metadata, give the requiredPermission field in propertySetConfig, or the RequiredPermission field in a Vlocity DataPack, a non-empty value.

An org-wide DefaultRequiredPermission covers components that name none of their own, but the rule still reports them, because the metadata under review carries no permission.

When should I disable this rule?

Dismiss individual issues for components that are deliberately open and expose nothing sensitive — an Integration Procedure returning reference data every user may already see, for example. If you control access entirely through another mechanism, you may find the rule reports issues you consider acceptable.

Resources

Did this answer your question?