AGENTFORCE-SEC-03: Apex Entry Point Exposes or Mints Integration Tokens
๐จ Critical ยท Credential Exposure
Detects @AuraEnabled, @RemoteAction, REST and invocable Apex methods that return OAuth access tokens or secret field values to the caller, and guest-accessible methods that mint client-credentials, password or JWT tokens on the caller's behalf. Guest access is read from profiles and permission sets with a guest licence. Critical when a guest can receive the token, high otherwise.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-SEC-03 |
| Severity | Critical |
| Category | Credential Exposure |
| Compliance | SOC2_CC6, PCI_DSS |
Remediationโ
Never return tokens or secrets to client code. Make the callout server-side through a Named Credential / External Credential and return only the data the page needs. Remove the class from guest profiles unless anonymous access is required; if it is, scope the integration user to the minimum objects and fields and rate-limit the endpoint. Rotate any token or secret that has been exposed.