That’s a good point…
I never like to rely solely on privacy rules to restrict what data is loaded… (that’s what search constraints are for).
I’ve seen apps that don’t use any search constraints… and just use privacy rules to restrict data to, say, only data created by the current User.
That’s fine (I guess) but if the privacy rules change at some point (or they are incorrectly set up, as is often the case), then it can cause problems.
So a combination of correct search constraints, plus robust privacy rules is best (in my opinion).
3 Likes