Information Packs may also change into orphaned, for instance, if the person creating them presses the cancel button throughout the course of. On this case, their attachments get created and by no means eliminated. Worse, they aren’t listed on the Information Packs stock web page in OmniStudio, making it more durable for admins to detect them.
When embedded in an exterior web site, FlexCard or OmniScript elements want an entry token to entry Salesforce. These tokens have to be created utilizing an OmniOut app. Nevertheless, a web site’s end-user can examine the API requests regionally of their browsers and extract this token, which may then be misused. Costello recommends that corporations use a proxy for communication between exterior OmniStudio elements and Salesforce.
A proxy, nonetheless, received’t assist when the token itself is embedded in OmniOut code that has been compromised or saved in public model management programs like GitHub. Moreover, a proxy may introduce dangers if it’s poorly configured to ahead requests with out validation, as customers may try to tamper with parameters and values.