question

NVinodhNarayanan-0495 avatar image
0 Votes"
NVinodhNarayanan-0495 asked MichaelHan-MSFT commented

Restrict select = "*" from SharePoint REST API

Hello Techies,

Is there any way to restrict select="" query from SharePoint REST API. Currently we are querying only selected columns using select query. Client tried to put select ="" via PostMan utility to check it retrieve all the columns to the user and raising this as a security issues

Fellow techies need your assitance on this.


Regards
Vinodh Narayanan.

office-sharepoint-onlineoffice-sharepoint-server-development
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MichaelHan-MSFT avatar image
0 Votes"
MichaelHan-MSFT answered MichaelHan-MSFT commented

Hi @NVinodhNarayanan-0495,

No, we can't. This is by design that we can use $select=* to return all available fields.

You could read the documentation here: https://docs.microsoft.com/en-us/sharepoint/dev/sp-add-ins/use-odata-query-operations-in-sharepoint-rest-requests#select-fields-to-return



If an Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@NVinodhNarayanan-0495,

Is there anything update on this issue? I'm willing to hear from you :)

0 Votes 0 ·