- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
There's a terminology in cybersecurity known as TOCTOU- Time Of Check to Time Of Use.
This concept means that when a resource's condition is checked and when it is actually used, there should not be a change in the conditions that was checked earlier to the time it got executed, which would then open up for security vulnerabilities...
Async business rules execute on a similar line where a condition is checked and then put in the sys_trigger table for execution and there is a possibility that the condition may change or updated, and hence the condition needs to be verified again before final execution.
An OOTB system property does exist to neutralize this vulnerability but rarely used.
To have the checks in place create/update this system property to true: glide.businessrule.async_condition_check
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
