# CONDITIONS in an ACTIONS -\> SECURITY?

**URL:** <https://community.glideapps.com/t/conditions-in-an-actions-security/32712>\
**Category:** Ask for Help\
**Created:** [October 6, 2021, 9:05am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712 "2021-10-06T09:05:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![christoph](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/christoph/32/22794_2.png) [@christoph](https://community.glideapps.com/u/christoph)\
**Post date:** [October 6, 2021, 9:05am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/1 "2021-10-06T09:05:09Z")

</div>

We know that visibility conditions of tabs, buttons, elements, … should not be used as security feature.  
Meaning, a button with a visibility condition might not be secure.

But what about the conditions inside of an action. If that condition depends on a column in the user profile sheet. Would this be secure to prevent “non-eligible” users to trigger this action?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [October 6, 2021, 9:28am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/2 "2021-10-06T09:28:53Z")

</div>

I think what you mean in this part

> [@christoph](#):
>
> We know that visibility conditions of tabs, buttons, elements, … should not be used as security feature.

is that those won’t necessarily protect your data, only row owners and roles (Private Pro) can fully secure it, not visibility conditions.

Or do you mean another type of “security”?

---

<div class="post-metadata">

**Author:** ![christoph](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/christoph/32/22794_2.png) [@christoph](https://community.glideapps.com/u/christoph)\
**Post date:** [October 6, 2021, 9:42am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/3 "2021-10-06T09:42:50Z")

</div>

I agree, this was more a statement, but my question is the following:

> But what about the conditions inside of an action. If that condition depends on a column in the user profile sheet. Would this be secure to prevent “non-eligible” users to trigger this action?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [October 6, 2021, 10:19am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/4 "2021-10-06T10:19:43Z")

</div>

Well as long as you don’t allow users to download specific data then the action will be secured.

The bottom line is data security relies on row owners and roles. If you configure that part the right way then the other things will follow.

---

<div class="post-metadata">

**Author:** ![Maxim\_KM](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maxim_km/32/29274_2.png) [@Maxim\_KM](https://community.glideapps.com/u/Maxim_KM)\
**Post date:** [October 6, 2021, 10:22am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/5 "2021-10-06T10:22:57Z")

</div>

Re data:  
I think everything delivers to clients, except data filtered out by Row Owners.

Re actions: if it’s on server side - it’s secure.  
For example: Trigger webhook, I hope it starts from Glide server.

---

<div class="post-metadata">

**Author:** ![christoph](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/christoph/32/22794_2.png) [@christoph](https://community.glideapps.com/u/christoph)\
**Post date:** [October 6, 2021, 11:59am UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/6 "2021-10-06T11:59:50Z")

</div>

It’s not only about downloading data, but also changing data.

Does this mean, that if I have a condition which “allows” certain users to trigger an action which e.g. sets column values, shows a detail screen, …, there is no way at all for other users to trigger this action?

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [October 6, 2021, 12:02pm UTC](https://community.glideapps.com/t/conditions-in-an-actions-security/32712/7 "2021-10-06T12:02:02Z")

</div>

Yes, as far as I aware, there’s not a way for you to mimic an action in the real app using some hacky ways in the browser.
