Encrypt Record IDs for Guest Users
For security reasons, don’t allow guest users to look up records by record ID unless you want the record to be public. When a guest user creates a record and wants to access it later, create an encrypted string that uses a combination of the record ID, record creation timestamp, and a current timestamp. The encrypted string acts as a unique identifier for the record that only the record creator has. At a later date, the Apex code that handles the request requires the guest user to submit the encrypted string. That Apex code decrypts the string to get the record ID and other record identifiers, and it retrieves or updates the requested record.
The User Encryption Decryption AppExchange package provides the UserCryptoHelper class, which uses the System.Crypto Apex library for the encryption and decryption, stores the related data for you, and provides two template flows. Use the managed package to implement customized record ID encryption, or create a similar managed package of your own.
See Also