← Salesforce Platform Developer: Apex and Lightning
06 / 8 · 40 MIN

Version-specific security and Visualforce interfaces

Review authorization and encoding without relying on old Apex assumptions.

Concept and mechanism

API version is part of security analysis. Current documentation states that database operations default to user mode in API 67; API 66 or earlier examples may rely on system mode. Declaring intent explicitly reduces ambiguity during upgrades. with sharing concerns record sharing and does not itself equal all CRUD and field-level security controls. Also review operation mode and the data contract. Security.stripInaccessible can support a response omitting inaccessible fields; the sanitized result must be used, with a decision on how to explain unavailable information.

Guided application

To expose Apex to LWC, the method must be static, public or global, and annotated with AuraEnabled; class access remains necessary. Do not turn an authorization failure into financial zeros or fix an experience regression by granting excessive access. In Visualforce, a controller extension can add behavior to a StandardController through the appropriate constructor while preserving relevant standard actions. Displaying external text requires context-appropriate encoding. Disabling escaping to display formatting can turn data into markup; HTML and JavaScript have different needs. Course examples do not generalize old system-mode statements across all versions or rely on a summarized trigger description that introduced ambiguity.

IN PRACTICE

After an API upgrade, a user can no longer read a restricted field. The team reviews the contract, omits the field where appropriate, and tests representative users. Forcing system mode merely to remove the message would contradict the access requirement.

Common pitfalls

with sharing treated as synonymous with FLS; sanitizing but returning the original list; labels or CSS treated as access controls; escape false for any authenticated text.

Related topics: Data model, identity, and metadata · Collections and choosing configuration or code · Queries, DML, and error outcomes

Take this idea with you

Identify version, identity, access mode, and output context. Authorization and presentation are distinct responsibilities.

Create account

Reference: Secure Apex Classes · Platform Developer guide Summer 25