Skip to main content

AGENTFORCE-SEC-03: Apex Entry Point Exposes or Mints Integration Tokens

๐Ÿšจ Critical ยท Credential Exposure

Detects @AuraEnabled, @RemoteAction, REST and invocable Apex methods that return OAuth access tokens or secret field values to the caller, and guest-accessible methods that mint client-credentials, password or JWT tokens on the caller's behalf. Guest access is read from profiles and permission sets with a guest licence. Critical when a guest can receive the token, high otherwise.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-SEC-03
SeverityCritical
CategoryCredential Exposure
ComplianceSOC2_CC6, PCI_DSS

Remediationโ€‹

Never return tokens or secrets to client code. Make the callout server-side through a Named Credential / External Credential and return only the data the page needs. Remove the class from guest profiles unless anonymous access is required; if it is, scope the integration user to the minimum objects and fields and rate-limit the endpoint. Rotate any token or secret that has been exposed.

See Alsoโ€‹