# Private Sign in, Limit Access by Email

**URL:** <https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992>\
**Category:** Ask for Help\
**Created:** [December 17, 2020, 2:54pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992 "2020-12-17T14:54:07Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 18, 2020, 7:56am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/21 "2020-12-18T07:56:46Z")

</div>

Okay, so I think the way to fix this is to set the email column on your Business Owners sheet as the row owner. That should sort out your visibility issue with the button.

But… based on what I’ve seen from your other posts it may introduce another problem, which is that individual business owners wont be able to see information about other businesses - and that _would_ be a problem, yes?

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 18, 2020, 8:12am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/22 "2020-12-18T08:12:45Z")

</div>

Yes, I looked into the row owners, all rows must to visible to all users of the app.

I have specific items I will add behind that button that are visible based on signed in email address.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 18, 2020, 8:29am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/23 "2020-12-18T08:29:39Z")

</div>

Okay.

Let me first preface this by saying that what follows is not much more than me thinking out aloud, and there is every chance that I could be wildly off base.

With that said…

I’ll assume first that within your Business Owners table there is a mix of information about each business. Some of this you want to make public, but some should be kept private and only accessible by individual business owners. If that’s not true, then you can probably stop reading here. Otherwise, read on…

If there is _any_ private information in the Business Owners sheet, then you _definitely_ should be using row owners on that table. But then, how do you make the “public” information available?

This is what I would do:

- Create a 2nd sheet, let’s call it Business Owners Public
- The first column of this sheet would be an arrayformula, which copies the RowID from the private table
- You use this column to create a relation between the two tables
- With that in place, you can add a lookup column to bring in each column from the private table that you want to make public
- You do not set any row owner on this table, so all data is accessible by anyone

Then with the above in place, anywhere in your app you need to display “public” business owner data, you reference this sheet instead of the “private” sheet.

This is a very similar approach to what @kyleheney described [here](https://community.glideapps.com/t/action-to-set-column-in-non-row-owned-column/19348), and to my simple mind it is both sound and secure.

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 18, 2020, 4:16pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/24 "2020-12-18T16:16:55Z")

</div>

OK thank you! I will try this.

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 18, 2020, 4:34pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/25 "2020-12-18T16:34:11Z")

</div>

If I switch the sheet being used to pull data for the app, will all of my components and styles be reverted back to default?

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 18, 2020, 6:59pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/26 "2020-12-18T18:59:04Z")

</div>

Ok I worked through this. Instead of re-doin my entire app, any other options to make one column secure/not visible to public users? Visibility isn’t enough?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 18, 2020, 7:03pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/27 "2020-12-18T19:03:26Z")

</div>

> [@Jen\_NYCP](#):
>
> If I switch the sheet being used to pull data for the app, will all of my components and styles be reverted back to default?

No, that shouldn’t happen. You will just need to reconfigure the existing components and point them at the new sheet.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 18, 2020, 7:09pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/28 "2020-12-18T19:09:33Z")

</div>

> [@Jen\_NYCP](#):
>
> Ok I worked through this. Instead of re-doin my entire app, any other options to make one column secure/not visible to public users? Visibility isn’t enough?

The problem with visibility is that _all_ data is still downloaded to the users device, and then the visibility settings “hide” the data from them. But it’s still there, and a savvy user will know how to get at it quite trivially. As an app developer, this leaves you exposed, and so you need to decide if you’re willing to take the risk that somebody might get hold of that data (and the potential consequences that might bring).

Using visibility to ‘restrict’ data access is good example of what’s commonly referred to as [Security through Obscurity](https://en.wikipedia.org/wiki/Security_through_obscurity).

But when you use row owners, then _only_ the data that belongs to that user is downloaded to their device. The rest stays on the Glide servers - and so it’s much _much_ more difficult for a bad actor to get at it.

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 18, 2020, 7:13pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/29 "2020-12-18T19:13:50Z")

</div>

Yes, Yes I get that 100%. I am working through adding all the lookup columns, I see I can’t give the headers the same name?

Also, for the private sheet, I will still want the email address column viewable by other businesses so that they can communication with each other via email (this won’t work with row owners) If I have this sheet behind the button which is only seen when a business is signed in, can a savvy public user access this sheet as well?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 18, 2020, 7:18pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/30 "2020-12-18T19:18:52Z")

</div>

> [@Jen\_NYCP](#):
>
> Yes, Yes I get that 100%. I am working through adding the lookups, I see I can’t give the headers the same name?

Where are you adding these lookups?  
It may not have been obvious, but my suggestion was to create the lookups in the Glide table.  
So when you are done with the “Public” sheet and you look at the Google Sheet - you will only see one column, which is the RowID with the arrayformula. All the rest will be computed columns that only exist in Glide.

You should be able to give those columns any name you like.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 18, 2020, 7:22pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/31 "2020-12-18T19:22:43Z")

</div>

> [@Jen\_NYCP](#):
>
> Also, for the private sheet, I will still want the email address column viewable by other businesses so that they can communication with each other via email (this won’t work with row owners) If I have this sheet behind the button which is only seen when a business is signed in, can a savvy public user access this sheet as well?

I’m not 100% sure about that one, so I’d defer to somebody with a much deeper understanding than me (looking innocently at @Jeff_Hager 😇)

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 18, 2020, 7:36pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/32 "2020-12-18T19:36:27Z")

</div>

Oh yes, I am creating them in the public sheet via the Glide data editor.

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [December 19, 2020, 12:26am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/33 "2020-12-19T00:26:53Z")

</div>

Unless you have a row owner or roles setup then that data is exposed.

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 19, 2020, 12:59am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/34 "2020-12-19T00:59:11Z")

</div>

Even for sheets not synced for data unless you are signed in? Where those who are signed are allowed to see that information.

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [December 19, 2020, 1:32am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/35 "2020-12-19T01:32:26Z")

</div>

I’m not totally sure on that answer. I just go under the assumption that any data that is not behind row owners or a secure private login is susceptible to being snooped by a savvy user regardless if they can access that part of the app or not. I’m not sure at what level the database is cached on the user’s device, but I would assume that most, if not all, data is synced and downloaded to the device to provide speed and ease of use to the end user. Row owners prevent that download from happening for users that are not meant to see that data. Like you said security through obscurity is not security at all.

Case in point is the recent post where a fellow app builder was notified by an anonymous user that all user data was accessible through various techniques, even though it was not technically visible in the app ui.

> [@How can I protect my app’s user profiles?](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980):
>
> A random person online has downloaded my full user database right after receiving access to my app. He sent me the list of my users in a txt file - I was literally shocked. Thank God it doesn’t seem to appear “ransomware” but more of a lead gen tactic - he wants to sell me cyber security services. After a bit of research and chatting with a technical friend, he told me that he might have performed UserEnum tactics to reverse engineer all my sign-ups. He has also told me that this issue could…

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 19, 2020, 2:34am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/36 "2020-12-19T02:34:18Z")

</div>

I see.

Three questions…  
Is it the glide editor or google sheet that downloads onto someone’s phone?

How can I have the email address column accessible and able to send emails for all business owners once they sign-in?

Do you know how long this data is cached? If I switch my public synced sheet to this more secure one, the old one might still be downloaded on some phones.

Thanks!

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [December 19, 2020, 3:16am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/37 "2020-12-19T03:16:43Z")

</div>

> [@Jeff\_Hager](#):
>
> I just go under the assumption that any data that is not behind row owners or a secure private login is susceptible to being snooped by a savvy user regardless if they can access that part of the app or not.

Correct. As long as the data is downloaded to the device (means it’s not protected by row owners or roles), it’s exposed.

It took me just 2 minutes to get to @Jen_NYCP’s app and get (I think) all data that is stored on the Sheet. It’s not secured.

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [December 19, 2020, 3:48pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/38 "2020-12-19T15:48:25Z")

</div>

It’s the same data you would see in the glide data editor. All computed columns are always computed locally on the user’s device. Not on the glide servers.

Are the emails only supposed to be accessible to other business owners and not the public? What data needs to be protected?

I have no idea how long it’s cached or if the cache is cleared after a user signs out of the app. It could all depend on the browser. All websites cache data within the browser but I assume it’s updated when a user is using the app.

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 19, 2020, 4:04pm UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/39 "2020-12-19T16:04:51Z")

</div>

Yes, the email address, and two others actually should be secure or not accessible by the public (not sure if that is the same thing) But I would like the other business to access the name and email address column of other businesses for contact.

---

<div class="post-metadata">

**Author:** ![Jen\_NYCP](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@Jen\_NYCP](https://community.glideapps.com/u/Jen_NYCP)\
**Post date:** [December 20, 2020, 3:18am UTC](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992/40 "2020-12-20T03:18:48Z")

</div>

Does anyone have their users contact each other via email?

[Previous page](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992.md?page=1)

[Next page](https://community.glideapps.com/t/private-sign-in-limit-access-by-email/19992.md?page=3)
