Sample Code Without Sharing: Give Guest Users Access to Create and Read Records in the Same Transaction

In this collection of code samples, the guest user enters details to report a support issue and Apex code creates a case. An Apex method retrieves the new record and Aura components display parts of the record to the guest user after creation. The Apex code runs without sharing because we aren’t relying on object permissions and platform sharing to allow the guest user to access the record.

Aura Component: CreateCase.cmp 

This sample Aura component displays several components where the user enters details about the case. After creation, the lightning:card component displays the new case’s case number and status.

1<aura:component controller="GuestUserCreateCase">
2
3    <aura:attribute name="caseNumber" type="String"/>
4    <aura:attribute name="status" type="String"/>
5    <aura:attribute name="subject" type="String" default=""/>
6    <aura:attribute name="description" type="String" default=""/>
7    <aura:attribute name="email" type="String" default=""/>
8    <aura:attribute name="name" type="String" default=""/>
9    <aura:attribute name="reason" type="String"/>    
10    <aura:attribute name="type" type="String" default=""/>
11
12    <lightning:select name="select" label="Reason" required="true" value="{!v.reason}"  aura:id="reason">
13        <option value="installation">Installation</option>
14        <option value="equipmentcomplexity">Equipment Complexity</option>
15        <option value="performance">Performance</option>
16        <option value="breakdown">Breakdown</option>
17        <option value="equipmentdesign">Equipment Design</option>
18        <option value="feedback">Feedback</option>
19        <option value="other">Other</option>
20    </lightning:select>
21    
22    <lightning:select name="type" label="Type" required="true" value="{!v.type}"  aura:id="type">
23        <option value="mechanical">Mechanical</option>
24        <option value="electrical">Electrical</option>
25        <option value="electronic">Electronic</option>
26        <option value="structural">Structural</option>
27        <option value="other">Other</option>
28    </lightning:select>
29    
30    <lightning:input type="email" name="email" required="true" value="{!v.email}" aura:id="email" label="Where should we send email updates?"/>
31    <lightning:input name="name" label="Name" required="true" value="{!v.name}" aura:id="name"/>
32    
33    
34    <lightning:input name="subject" label="Subject" required="true" value="{!v.subject}" aura:id="subject"/>
35    <lightning:textarea name="description" required="true" label="Description" value="{!v.description}" aura:id="description"/>
36    
37    <lightning:button name="submit" variant="brand" label="Submit case" title="Submit case" onclick="{!c.submitCase}"/>
38    
39    <aura:if isTrue="{!v.caseNumber}">
40        <lightning:card title="Case">
41            <p class="slds-p-horizontal--small">
42                {!v.caseNumber} has status {!v.status}.
43            </p>
44        </lightning:card>
45    </aura:if>
46</aura:component>

Component Controller: CreateCaseController.js 

This sample JavaScript controller processes events for the Aura component and calls the methods in the helper file.

1({
2    submitCase : function(component, event, helper) {
3        helper.makeCase(component, event, helper);
4    }
5})

JavaScript Helper: DisplayCaseHelper.js 

This JavaScript helper creates an asynchronous request to create a case with the submitted data. When the request completes, the callback stores the case number and case status in variables used by the Aura component.

1({
2        makeCase : function(component, event, helper) {
3            var subject = component.get("v.subject");
4            var description = component.get("v.description");
5            var email = component.get("v.email");
6            var name = component.get("v.name");
7            var reason = component.get("v.reason");
8            var type = component.get("v.type");
9
10            
11            var action = component.get("c.CreateCase");
12            action.setParams({
13                "subject": subject,
14                "description": description,
15                "email": email,
16                "name": name,
17                "reason": reason,
18                "caseType": type
19            });
20            action.setCallback(this, function(response){
21                component.set("v.caseNumber", response.getReturnValue()[0]);
22                component.set("v.status", response.getReturnValue()[1]);
23            });
24            $A.enqueueAction(action);
25        }
26})

Apex Controller: GuestUserCreateCase.apxc 

This sample Apex controller creates the record, retrieves the new record, and returns the required fields from the new record to the client. Because object permissions and platform sharing aren’t used, this controller runs without sharing.

To avoid unintended exposure of record data, the CreateCase method returns only the CaseNumber and Status fields.

Any system or individual on the internet can invoke @AuraEnabled classes. Make sure that the method returns only the required fields from the new record.

Note

1public without sharing class GuestUserCreateCase {
2    
3    @AuraEnabled
4    public static List<String> CreateCase(String subject, 
5                                         String description, 
6                                         String email,
7                                         String name,
8                                         String reason,
9                                         String caseType,
10                                         String phone){
11		Case new_case = new Case(Subject=subject, 
12                                 Description=description,
13                                 SuppliedEmail=email,
14                                 SuppliedName=name,
15                                 Reason=reason,
16                                 Type=caseType,
17                                 SuppliedPhone=phone);
18        insert new_case;
19                                             
20        List<Case> results = getCase(new_case.Id);
21
22        List<String> response = new List<String>();
23        response.add(results[0].CaseNumber);
24        response.add(results[0].Status);
25        return response;
26
27    }
28
29private static List<Case> getCase(String caseID)
30{
31    List<Case> results = [SELECT CaseNumber, Status 
32	FROM Case 
33    WHERE Case.Id=:caseID];
34    return results;
35}
36
37}

See Also