Give Guest Users Access to Update Records

To allow guest users to update records, perform the action in the system context without sharing. Before you allow a user to update a record, verify an encrypted token previously provided to the user as a best practice. To ensure that it’s the correct record, verify information about the record, such as its creator.

The Summer ’20 release added new settings and updated guidelines for guest user record access. As of Winter ’21, the guidelines introduced with the Summer ’20 update are enforced. After the Winter ’21 release, you must use the without sharing mode because you can’t use sharing rules to grant guest users update access to records..

Note

Lightning Components and Guest Users 

Lightning components that link directly with an object’s fields automatically perform object permissions and field-level security (FLS) checks to determine whether the components display for the user. If you have the Secure guest user record access setting enabled, then you can’t give guest users access to update records. In that scenario, object permission checks that require update permissions fail and the components don’t display.

To use Lightning components to handle guest user input, use variables to set the values of the Lightning components. Then separately associate those variables with the record’s fields in the Apex code. Because this method works around the automatic object permissions and FLS checks, implement your Lightning components with these guidelines:

  • Use server-side code to retrieve the record and verify it’s the record that you want to update before you perform the update.
  • Don’t pass record fields to the client unless you want to display them to the user. Any data you send to the client is public.
  • Don’t pass record IDs to the client. Don’t accept record IDs from the client. To create a unique identifier for a record, encrypt the record ID as a string.
  • Use server-side logic to restrict the update to only the desired fields. Don’t use client-side code to determine server-side behavior.
  • Use server-side logic to validate data from the client before the code performs the update.

See Also