SPC025501: Do not set 'AllowEveryoneViewItems' to TRUE in ListDefinition

The attribute ListAllowEveryoneViewItems of a ListDefinition should not be set to true, as it allows every authenticated user of the web application to access the list items when the URL is known.

TypeName: DoNotSetAllowEveryoneViewItemsToTrue
CheckId: SPC025501
Severity: CriticalWarning
Type: ListTemplateDefinition
Resolution

The attribute 'AllowEveryoneViewItems' of the SPList object should not be set to true, as it allows every authenticated user of the web application to access the list items when the URL is known.

comments powered by Disqus