Web to Lead Forms security

Hi! I was wondering if there is a secure way to use Web to Lead forms in SugarCloud.

I mean, anyone can extract the API url from the form and start making customised calls, right?

Can we set up an IPs whitelist for the API rest or something similar?

One of our customers is worried about this and we haven't known what to answer as it seem a legitim concern.

I have already seen these links which can lead to different solutions:

Am I missing something? because it seems that Sugar is proposing a solution which basically exposes our sites to a security breach.

Thanks

Parents
  • Are you talking about on premise? Or a cloud release? Either way you should check the advanced configuration section of the admin guide. Maybe, I haven't tested it yet, you can utilize the http_referer setting in the config. And if it's on premise you could always configure the server itself to allow only connections from a few ip addresses / domains

  • Thanks, It's on SugarCloud

Reply Children