# Edit Security Question

**URL:** <https://community.glideapps.com/t/edit-security-question/29460>\
**Category:** Ask for Help\
**Created:** [July 23, 2021, 12:31am UTC](https://community.glideapps.com/t/edit-security-question/29460 "2021-07-23T00:31:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kriss](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kriss/32/16657_2.png) [@Kriss](https://community.glideapps.com/u/Kriss)\
**Post date:** [July 23, 2021, 12:31am UTC](https://community.glideapps.com/t/edit-security-question/29460/1 "2021-07-23T00:31:10Z")

</div>

Hi team, I have a question about Glide’s security around data edits.

I have a table that should be _viewed_ by all users, and rows in that table are _created_ by users. For allowing users to edit rows, I’ve already set up visibility settings for _editing rows_ around “does user email match row creator email”.

My concern is this: As glide downloads the full sheet, I worry that a bad actor could potentially change a row that they do not own, through inspect element or other circumvention of the visibility of the edit elements.

Having rows that are _visible_ to all users but _editable_ by only some users, and ensuring that data is secure and cannot be compromised is a key requirement of my app.

Is this something that Glide supports or should I look at another solution for this type of security? Can _view_, cannot _edit_.

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [July 23, 2021, 12:41am UTC](https://community.glideapps.com/t/edit-security-question/29460/2 "2021-07-23T00:41:04Z")

</div>

> [@Kriss](#):
>
> I worry that a bad actor could potentially change a row that they do not own, through inspect element or other circumvention of the visibility of the edit elements.

Just to be clear, inspecting elements on a public table does not mean it’s possible to change the source data. Only you and people who have access to the underlying Sheet/Glide Table can do that.

You are structuring the right condition for the editing part, so I don’t think there’s something to be worried about here.

The editing element is only generated by Glide when conditions are matched. As far as I aware, adding things in the source code does not grant the ability to mimic that button.

---

<div class="post-metadata">

**Author:** ![Kriss](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kriss/32/16657_2.png) [@Kriss](https://community.glideapps.com/u/Kriss)\
**Post date:** [July 23, 2021, 12:44am UTC](https://community.glideapps.com/t/edit-security-question/29460/3 "2021-07-23T00:44:03Z")

</div>

Awesome, thanks. So to confirm, does Glide perform any sort of back-end authentication when receiving an edit request? I.e. someone can’t spoof an edit request and the server will consume it?

I want to make sure that only users that _created_ rows can _edit_ those rows, but as for presentation that’s less of a concern, as all rows should be public anyways.

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [July 23, 2021, 12:50am UTC](https://community.glideapps.com/t/edit-security-question/29460/4 "2021-07-23T00:50:45Z")

</div>

I can’t say for sure about that back-end authentication, but on the front-end only users you allow to edit can edit anyway.

---

<div class="post-metadata">

**Author:** ![Kriss](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kriss/32/16657_2.png) [@Kriss](https://community.glideapps.com/u/Kriss)\
**Post date:** [July 23, 2021, 1:04am UTC](https://community.glideapps.com/t/edit-security-question/29460/5 "2021-07-23T01:04:08Z")

</div>

That’s good enough for me for now. Thanks for the help!

---

<div class="post-metadata">

**Author:** ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)\
**Post date:** [July 23, 2021, 12:50pm UTC](https://community.glideapps.com/t/edit-security-question/29460/6 "2021-07-23T12:50:54Z")

</div>

Glide has a bunch of security checks on the backend.

Most importantly, it will never allow editing a row in a table that has row owners, where the row is not owned by the logged-in user.

---

<div class="post-metadata">

**Author:** ![laszlo](https://avatars.discourse-cdn.com/v4/letter/l/cc9497/32.png) [@laszlo](https://community.glideapps.com/u/laszlo)\
**Post date:** [July 3, 2022, 6:18pm UTC](https://community.glideapps.com/t/edit-security-question/29460/7 "2022-07-03T18:18:40Z")

</div>

I would like to pick up the topic again.

As mentioned in the Security Center documentation of Glide: The visibility conditions are just so the end-user does not see specific elements. Like not “see” an edit button → not stop the underlying network requests which can be manipulated by any one with coding/network understanding.

1. 

> @ThinhDinh  
> The editing element is only generated by Glide when conditions are matched. As far as I aware, adding things in the source code does not grant the ability to mimic that button.

A potential bad actor does not need to look or change the source-code, they look at the network requests and can manipulate a request to tell the server to store potentially any element or data.

1. 

> @Mark  
> Most importantly, it will never allow editing a row in a table that has row owners, where the row is not owned by the logged-in user.

Although, this is true for a column with a ‘Row Owner’, the use case which the topic owner describes is different: **All can see, only specific users can edit**

Does not allow the use of a Row Owner, as this would prevent every user to see all data.

1. 

> @Mark  
> Glide has a bunch of security checks on the backend.

When inspecting the network traffic of an edit request (when the user clicks save/ready), the browser directly sends data to the Google Firestore API, which is NOT the Glide server, it’s directly connecting to the database.

It is possible to set up security rules within a Google Firestore database, the question would just be if these are automatically set when we create a “condition” in the Glide interface for the Edit/Add buttons?

1. 

Then there is still the “Visibility is not a security feature” dialog warning which pops up as soon as you try to add a condition for edit/add-form the Gilde interface

* * *

There are still lots of unknowns and I would appreciate a clear answer from the Glide team as this is security-relevant!

Thank you 🙏

---

<div class="post-metadata">

**Author:** ![NoCodeAndy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nocodeandy/32/62530_2.png) [@NoCodeAndy](https://community.glideapps.com/u/NoCodeAndy)\
**Post date:** [January 17, 2024, 4:49pm UTC](https://community.glideapps.com/t/edit-security-question/29460/8 "2024-01-17T16:49:27Z")

</div>


