Post

Power Pages BYOC: Secure React sites with Dataverse access controls

Diesen Beitrag auf Deutsch lesen

A tutorial for hosting React code in Power Pages while configuring Web API exposure, CSRF protection, authentication and Dataverse permissions.

TL;DR

Power Pages single-page applications can host a React site while retaining Power Pages authentication and Dataverse security. The tutorial enables selected Web API tables and fields, uses a CSRF token helper, configures table permissions and web roles, adds Entra External ID sign-in, and limits records to the signed-in user.

Original by Nick Doelman, on ReadyXRM Blog. Read the original

This is our own summary, not a republication or full translation.

Governance takeaway

  • Makers: Build and test React sites in a non-production Power Platform environment, then verify the generated code and Web API behavior before deployment.
  • Admins/CoE: Enable only required Dataverse tables and columns, avoid using an asterisk for fields, and configure table permissions and web roles explicitly.
  • Security/Compliance: Require CSRF tokens for Web API calls and test unauthenticated, authenticated and signed-out access so users cannot retrieve records belonging to others.
  • Leadership/Business: Treat the coded front end as an extension of Power Pages controls, not a replacement for its hosting, authentication and data security model.
This post is licensed under CC BY 4.0 by the author.