Since custom backend workflows are being able to be triggered from the front and we can use that data, I’m excited that Bubble is going to the right way in development. But this may lead to some security problems, the data is not secure, at least the results or steps in that custom event. Hopefully, the return data from scheduling api’s can do the same in a near future.
Yep, we called this out in the main feedback thread. Needs to be addressed for sure.
Why wouldn’t they be secure?
The workflow is triggered from the frontend, but it runs entirely on the backend. The only thing returned to the client is the final result.
None of the data exchanged between the actions within that workflow is visible or accessible to the end user.
This previously wasn’t true, but the team deployed a patch yesterday ![]()
Now, only the value returned from the custom event is returned.
Didn’t know they have made it wrong ![]()
Great to know! Thanks @fede @emmanuel @nick.carroll for listening the community ![]()