<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Salesforce Developer Forums - Security</title><link>https://developer.salesforce.com/forums</link><atom:link rel="self" href="https://dfc-org-production.my.site.com/forums/ForumsRSS?category=Security" type="application/rss+xml"></atom:link><description>This is the main RSS feed for the Salesforce Developer Forums</description><lastBuildDate>Tue, 05 May 2026 17:14:30 +0000</lastBuildDate><item><title>I am blocked on Trailhead because I have started multiple Developer Edition orgs, do not have the login credentials for them, they say my city of birth is wrong, and because they are not linked I cannot enter a help ticket to get them  deactivated.</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Mon, 20 Nov 2023 00:16:04 +0000</pubDate><dc:creator>Corinna Takigawa</dc:creator><guid isPermaLink="false">9065d000000NrSkAAK</guid><description><![CDATA[I need a Developer Edition account for my next superbadges and some regular badges as well.<br>Yet, I cannot start anymore because my emails are linked to some.<br>I cannot open any of the DE&#39;s I&#39;ve had.<br>I can get all the way in to one or two of them to where there should be a &quot;Deactivate Org&quot; button but there is no button showing, so I think I&#39;m not the admin.<br>So I cannot deactivate the orgs to start new ones for the challenges/superbadges I want to do.<br>Resetting password does not work because it always says the city I was born in is wrong.<br>I cannot submit a help ticket because that must be linked to an org.  Yet I cannot link these because I don&#39;t have full access to them.<br>I am working very hard, have earned Double Star Ranger and one superbadge, but now feel entirely blocked from moving forward with goals.  Please advise.]]></description></item><item><title>can not login salesforce</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Thu, 16 Nov 2023 07:55:25 +0000</pubDate><dc:creator>CUI Captain</dc:creator><guid isPermaLink="false">9065d000000NrPRAA0</guid><description><![CDATA[Hello,<br><br>I am the only admin of my ORG and the system is set up to require two-factor authentication.<br> <br>I&#39;ve made a change in the setup -&gt; session settings, and move the two-factor authentication from the High Assurance column to the Standard column. <br><br>I&#39;ve logged out and can not login. <br>I got an error message as bellow:<br>To log in, you need both a higher access level and an identity verification method. Contact your administrator to gain login access.<br><br>How do i solve it and login?<br><br>Thanks for you time and best regards,<br>captain]]></description></item><item><title>Resolving SOQLInjection error</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Thu, 09 Nov 2023 16:50:03 +0000</pubDate><dc:creator>Tejaswini E</dc:creator><guid isPermaLink="false">9065d000000NrJOAA0</guid><description><![CDATA[Hi Team, Is it possible to  resolve SoqlInjection error for the below code without adding String.escapeSingleQuotes() in Database.query(query)<br><br>String query = &#39;SELECT Id, Subject, Description, ActivityDate, Status, WhatId, What.Name, Type, Priority FROM Task WHERE&#39;;<br>        if (recordId != null) <br>            <br>            query += &#39; WhatId = :recordId AND TaskSubtype != \&#39;Email\&#39; ORDER BY &#39; + sortOrder; <br>        else {<br>            String ownerId = UserInfo.getUserId();<br>            query += &#39; OwnerId=:ownerId AND TaskSubtype != \&#39;Email\&#39; AND Status NOT IN(\&#39;Completed\&#39;, \&#39;Withdrawn/Canceled\&#39;)&#39;; <br>        }<br><br>        for(Task t : Database.query(query))]]></description></item><item><title>consumer key and secret have been changed twice after refresh environment</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Fri, 03 Nov 2023 06:24:46 +0000</pubDate><dc:creator>yang li 53</dc:creator><guid isPermaLink="false">9065d000000NrCNAA0</guid><description><![CDATA[I refresh my uat full environment,and after refreshed successfully,I generated new consumer key and secret, but after about a week later, the key and secret has been changed.now I have two questions:<br>1.When I generate new key and secret, I didn&#39;t find the button &#39;generate&#39;,It looks like differtent from the document,Rotate the Consumer Key and Consumer Secret of a Connected App (<a href="https://help.salesforce.com/s/articleView?id=sf.connected_app_rotate_consumer_details.htm&amp;type=5https://help.salesforce.com/s/articleView?id=sf.connected_app_rotate_consumer_details.htm&amp;type=5" target="_blank">https://help.salesforce.com/s/articleView?id=sf.connected_app_rotate_consumer_details.htm&amp;type=5https://help.salesforce.com/s/articleView?id=sf.connected_app_rotate_consumer_details.htm&amp;type=5</a>)<br>2.I think the key and secret cannot be changed normally expect of I refresh the environment, Why it can be changed,and I test once more,I change key and secret twice in three hours,It hasn&#39;t been changed, Is there a need for a certain time interval between two builds？<br> ]]></description></item><item><title>Not receiving Verification code from UI Login</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Fri, 27 Oct 2023 15:08:23 +0000</pubDate><dc:creator>Navin Yadav</dc:creator><guid isPermaLink="false">9065d000000Nr5lAAC</guid><description><![CDATA[I have a site on experience builder, I have 2 sandboxes dev and sit, In dev when I try to log in from UI I am receiving an verification code on my email but when I do the same in SIT, I am directly getting logged in without verification code, I want verification code on my email in SIT as well.<br>I compared the following settings in DEV and SIT and both are identical
<ul><li>Identity verifications - MFA as high assurance</li><li>Session Settings - Require MFA for UI</li><li>Profile level System permissions</li></ul>
Can anyone suggest what I could have missed here?]]></description></item><item><title>I am able to see few record types in my account object and able to create record successfully with them even though the roles has read access</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Thu, 26 Oct 2023 08:13:07 +0000</pubDate><dc:creator>Sreelakshmi Asokan</dc:creator><guid isPermaLink="false">9065d000000Nr3aAAC</guid><description><![CDATA[Hello Everyone,<br><br>So I have 2 UAT environments, in one I am able to see and create records of particular record types which has read access only while in another environment i cant see or create records. Have gone through OWD, SHARING Rules, Permission sets public group and didnt find anything. Can someone please help me with this]]></description></item><item><title>SAML SSO: Salesforce IDP + Connected App config: How can I find the Persistent ID and store in custom field on User object?</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Wed, 25 Oct 2023 23:05:03 +0000</pubDate><dc:creator>crowdforce</dc:creator><guid isPermaLink="false">9065d000000Nr3LAAS</guid><description><![CDATA[Hi Community - Looking for some help on a very niche topic. <br><br>Question: We use The <strong>Persistent ID</strong> described under the section Subject Type in this SAML salesforce documentation (<a href="https://help.salesforce.com/s/articleView?id=sf.connected_app_create_saml_sso.htm&amp;type=5" target="_blank">https://help.salesforce.com/s/articleView?id=sf.connected_app_create_saml_sso.htm&amp;type=5</a>)<br><br>We now want to surface this value for each user and export it to our EDS. I have not been able to find any further docs on where or how to find this value per user within salesforce user object.<br><br>Anyone know how this can be done?]]></description></item><item><title>best practices for creating opportunities that can have limited view permissions</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Wed, 25 Oct 2023 19:46:48 +0000</pubDate><dc:creator>Vishal Kumar Singh 4</dc:creator><guid isPermaLink="false">9065d000000Nr3BAAS</guid><description><![CDATA[What is the best practice to be able to give users the ability to create confidential opportunities that can only be viewed by users they choose]]></description></item><item><title>Guest user facing issue "INSUFFICIENT_ACCESS_ON_CROSS_REFERENCE_ENTITY" in a site without login</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Tue, 24 Oct 2023 05:24:37 +0000</pubDate><dc:creator>abel reegan 28</dc:creator><guid isPermaLink="false">9065d000000Nr1AAAS</guid><description><![CDATA[Guest user facing issue &quot;INSUFFICIENT_ACCESS_ON_CROSS_REFERENCE_ENTITY&quot; in a site without login, even after profile level read access is given and sharing rule created for guest user profile, how can I debug this?<br><br>I tried to query in &quot;UserRecordAccess&quot; table for the guest user and it shows that the guest user has read access to that specific record.]]></description></item><item><title>Issue with Canvas App - Response header has X-Frame-Options : DENY</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Thu, 19 Oct 2023 15:02:58 +0000</pubDate><dc:creator>Chris Voge 17</dc:creator><guid isPermaLink="false">9065d000000NqxDAAS</guid><description><![CDATA[Hello,<br><br>I am trying embed our site using a Canvas app, it appears Salesforce is responding with X-Frame-Options : DENY  and  frame-ancestors: &#39;none&#39;  resulting in a gray screen.<br><br>I&#39;ve tried adding my site to Remote Site Settings and Trusted URLs on both classic and ExperienceBuilder. Doesn&#39;t seem to work.<br><br>Help would be appreciated. Thanks, Chris<br><br> ]]></description></item><item><title>Users being directed to MFA Verification login screen even though SSO is enabled</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Wed, 18 Oct 2023 18:20:38 +0000</pubDate><dc:creator>LOGAN FUENTES</dc:creator><guid isPermaLink="false">9065d000000NqvlAAC</guid><description><![CDATA[Users being directed to MFA Verification login screen below even though we have SSO enabled on our org, any setting updates on SSO needed to ensure bypass?]]></description></item><item><title>Object Security</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Sun, 15 Oct 2023 00:48:46 +0000</pubDate><dc:creator>santosh kumar 864</dc:creator><guid isPermaLink="false">9065d0000007CSzAAM</guid><description><![CDATA[Two users(user1 &amp; user2) have same profile. There is an object &#39;Laptops&#39;.<br>User1 have access to object.<br>User2 not to have access to object. Is it possible?<br><br>OWD - Private<br>Profile - C, R, E, D for object<br>There is no role hirerachy setup]]></description></item><item><title>InternalExecutionError: Salesforce Code Analyzer Report</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Tue, 10 Oct 2023 10:13:03 +0000</pubDate><dc:creator>Praveen Pujar 41</dc:creator><guid isPermaLink="false">9065d0000007CNfAAM</guid><description><![CDATA[Hello everyone, has anyone came across Internal Executions Errors like  OutOfMemory &amp; StackOverflowError issues while generating Salesforce code analyzer report ? I have increased the heap space and tried, issue still persists,  if anyone has fixed this issue or worked on code analyzer, please post your answer, thanks in advance.<br> <br>Command used - sfdx scanner:run:dfa --format=html --sfgejvmargs &quot;-Xmx20g&quot; --outfile=CodeAnalyzerDFA3.html --target=&quot;./&quot; --projectdir=&quot;./&quot; --category=&quot;Security&quot; --rule-thread-timeout 9000000]]></description></item><item><title>How to import Salesforce report to SharePoint or OneDrive</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Fri, 06 Oct 2023 08:28:06 +0000</pubDate><dc:creator>Princes91221</dc:creator><guid isPermaLink="false">9065d0000007CJsAAM</guid><description><![CDATA[Was wondering if anyone could advise on the best methodology to import Salesforce reports into SharePoint or OneDrive, so that multiple people can collaborate on the same report.<br>Currently we&#39;re not using a connector to SharePoint, and are looking to move away from this due to potential security risks.<br>Any advice or recommendations will be greatly appreciated, and thank you in advance!]]></description></item><item><title>A single Lead record not accessible as System Admin</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Thu, 21 Sep 2023 18:27:58 +0000</pubDate><dc:creator>AArora 50</dc:creator><guid isPermaLink="false">9065d0000007C1AAAU</guid><description><![CDATA[I have come across a Lead record that I am not able to access as a System Admin. None of the jobs running are able to access this record either. I need to run a job to process this record and it fails each time.  This record is owned by a Queue.<br><br>If I query the record in the Dev console using Standard fields I can access the data but if I include a custom field the data does not show up.<br><br>While accessing through UI I get following message<br>You do not have the level of access necessary to perform the operation you requested. Please contact the owner of the record or your administrator if access is necessary.<br><br>How can I access this record? ]]></description></item><item><title>I am trying to authorize an sandbox  org in vscode I am getting redirect tohttp://localhost:1717/OauthError   This is most likely not an error with the Salesforce CLI. Please ensure all information is accurate and try again.</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Wed, 20 Sep 2023 15:55:48 +0000</pubDate><dc:creator>Jayabalan n</dc:creator><guid isPermaLink="false">9065d0000007Bz4AAE</guid><description></description></item><item><title>Admin Password Reset</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Wed, 13 Sep 2023 16:57:26 +0000</pubDate><dc:creator>Kimberly Soutar</dc:creator><guid isPermaLink="false">9065d0000007Bs3AAE</guid><description><![CDATA[<p>How do I go about having my developer password reset by an admin?</p>

<p>I have tried to reset using the link, and after jumping through many hoops with Outlook, I finally got the link to work, but then it was asking me my security question. Where were you born, of which I am certain, but says the answer is incorrect. </p>]]></description></item><item><title>How to set up Delete access  exclusively to manager  using  data security ?</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Wed, 13 Sep 2023 03:00:05 +0000</pubDate><dc:creator>suji srinivasan</dc:creator><guid isPermaLink="false">9065d0000007BpxAAE</guid><description><![CDATA[Hi,<br>I need assistance with setting up delete access for sales managers in Salesforce.<br><strong>Here are my requirements:</strong><br>Edit Access: Sales managers should have the ability to edit all opportunities.<br>Record Types: Opportunities created by the Direct Sales team should use the &quot;Direct Sales&quot; record type, while those created by the Inside Sales team should use the &quot;Inside Sales&quot; record type.<br>View Access:<br>The Direct Sales team should be able to view all opportunities, regardless of the record type.<br>The Inside Sales team should only see opportunities belonging to their team.<br>Delete Access:<br>Both Direct Sales managers and Inside Sales managers should have the ability to delete all opportunities.<br><strong>Here&#39;s what I&#39;ve already done:</strong><br>Created five profiles: Sales Manager, Direct Sales Manager, Inside Sales Manager, Direct Sales Rep, and Inside Sales Rep.<br>Set the Organization-Wide Default (OWD) to &quot;Private.&quot;<br>Assigned record types based on profiles.<br>Used sharing rules with criteria to make Inside Sales team records accessible to that team.<br>Enabled the &quot;View All&quot; permission for the Direct Sales team.<br><br>Now, I need guidance on how to provide delete access exclusively to Direct and Inside Sales Managers.<br><br>Thanks ]]></description></item><item><title>Significance of Role Hierarchy</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Thu, 07 Sep 2023 09:00:05 +0000</pubDate><dc:creator>phanip admin</dc:creator><guid isPermaLink="false">9065d0000007BkTAAU</guid><description><![CDATA[Significance of Role Hierarchy <br>Scenario: In a organization Manager-A &amp; Subordinates, Manager-B &amp; Subordinates, Manager-C &amp; Subordinates. When ever any subordinate will create record, no other subordinate will have access, but all the managers should have access for all the records. how to solve this? ]]></description></item><item><title>I have url https://es-portal.gavi.org/sdgavi--uat/sdcs101/ in custom settings while redirecting to the url session id is not set in the cookie for that it always redirecting to login page</title><link>https://developer.salesforce.com</link><comments>https://developer.salesforce.com</comments><pubDate>Fri, 01 Sep 2023 12:26:09 +0000</pubDate><dc:creator>Data Integration 46</dc:creator><guid isPermaLink="false">9065d0000007BdcAAE</guid><description><![CDATA[<br>I have url https://es-portal.gavi.org/sdgavi--uat/sdcs101/ in custom settings while redirecting to the url session id is not set in the cookie for that it always redirecting to login page.From request header i got that session id is not set .But as expected salesforce should set the sid in cookie as we don&#39;t have control on request header.Can anyone please suggest why sid or session is not set?Below image is request header for the url<img alt="User-added image" src="/forums/servlet/rtaImage?eid=9065d0000007Bdc&amp;feoid=Body&amp;refid=0EM5d000007lvcJ" style="height: 197px; width: 500px;"></img>]]></description></item></channel></rss>