API grumble

posted Jan 26, 2015, 8:56 AM by Ezra Kenigsberg
Salesforce requires you to turn on API access for users to use doodads like Salesforce for Outlook.

This means they also have access to the full API, which means they can access ANY record that's ever been in the org (using getDeleted and queryAll). 

Bad bad bad! Vote for change.
Comments