We have a Powerapps Portal app to serve chemical industry level operations for multiple Chemical industries Employees.
However any Logged-In user able to access API call by simply inspect element -> Source via JavaScript and some URL operations.
Let me know how we can restrict API call so that no one can read other industry user data via javascript and URL operations.
Its an security issue.
Till now we have tried by implemented Ajax Web API call but now as per Portal update anyone can add portal url prefix to generated API URL from debugging javascript.
Appreciate quick response as its an High Priority.

Report
All responses (
Answers (