Power Pages BYOC: Secure React sites with Dataverse access controls
Diesen Beitrag auf Deutsch lesen
A tutorial for hosting React code in Power Pages while configuring Web API exposure, CSRF protection, authentication and Dataverse permissions.
TL;DR
Power Pages single-page applications can host a React site while retaining Power Pages authentication and Dataverse security. The tutorial enables selected Web API tables and fields, uses a CSRF token helper, configures table permissions and web roles, adds Entra External ID sign-in, and limits records to the signed-in user.
Original by Nick Doelman, on ReadyXRM Blog. Read the original
This is our own summary, not a republication or full translation.
Governance takeaway
- Makers: Build and test React sites in a non-production Power Platform environment, then verify the generated code and Web API behavior before deployment.
- Admins/CoE: Enable only required Dataverse tables and columns, avoid using an asterisk for fields, and configure table permissions and web roles explicitly.
- Security/Compliance: Require CSRF tokens for Web API calls and test unauthenticated, authenticated and signed-out access so users cannot retrieve records belonging to others.
- Leadership/Business: Treat the coded front end as an extension of Power Pages controls, not a replacement for its hosting, authentication and data security model.
