ãã©ã°ã€ã³ãšæ¡åŒµæ©èœã®éçºã®åéã§ã¯ãããã©ã°ã€ã³ã®ã»ãã¥ãªãã£ãã¯éçºè ãšãŠãŒã¶ãŒã®äž¡æ¹ã«ãšã£ãŠæãéèŠã§ããããã¯ãéçºè ãäœæãããã©ã°ã€ã³ãæ¡åŒµæ©èœãã飿ºããããã«èšèšãããã¢ããªã±ãŒã·ã§ã³ããšã³ããŠãŒã¶ãŒèªäœã«ã»ãã¥ãªãã£ã®è匱æ§ã䟵害ãåŒãèµ·ãããªãããã«ããããã«ãéçºè ãåŸããªããã°ãªããªãããŸããŸãªå¯Ÿçãååããã¹ã ãã©ã¯ãã£ã¹ãæããŸãããã®æŠå¿µã«ã¯ãæœåšçãªã»ãã¥ãªã㣠ãªã¹ã¯ã軜æžããããã®ããŒã¿ ãã©ã€ãã·ãŒãæå·åãèªèšŒãå®å šãªã³ãŒãã£ã³ã°ã®å®è·µãªã©ãå¹ åºãã»ãã¥ãªãã£äžã®èæ ®äºé ãå«ãŸããŠããŸãã
AppMasterããã¯ãšã³ããWebãããã³ã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãäœæããããã®åŒ·åãªno-codeããŒã«ã§ããããããã®ãã©ãããã©ãŒã ã¯ãéçºè ãæ§ç¯ãããã©ã°ã€ã³ãšæ¡åŒµæ©èœãå€éšãšå éšã®äž¡æ¹ã®è åšããå®å šã«ä¿ãããããã«æ¯æŽããããšã«å°œåããŠããŸãã AppMasterã®ã¢ãããŒãã«ã¯ãã¢ããªã±ãŒã·ã§ã³ãæåããèªåçã«çæããããšãå«ãŸããŠãããããã«ããããœãããŠã§ã¢éçºã§ããçºçããæè¡çè² åµãæé€ãããŸããããããããšã§ãããšã 1 人ã®åžæ°éçºè ã§ãã£ãŠããå æ¬çã§å®å šãã€ã¹ã±ãŒã©ãã«ãªãœãããŠã§ã¢ ãœãªã¥ãŒã·ã§ã³ãäœæã§ããããã«ãªããŸãã
ãã©ã°ã€ã³ã®ã»ãã¥ãªãã£ã®éèŠãªåŽé¢ã® 1 ã€ã¯ãå®å šãªã³ãŒãã£ã³ã°ææ³ãéµå®ããããšã§ããéçºè ã¯ããã©ã°ã€ã³ã«è匱æ§ãæã¡èŸŒãŸããã®ãé²ãããã«ã峿 Œãªã¬ã€ãã©ã€ã³ã«åŸãå¿ èŠããããŸããããšãã°ãã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã° (XSS)ãã¯ãã¹ãµã€ã ãªã¯ãšã¹ã ãã©ãŒãžã§ãª (CSRF)ãSQL ã€ã³ãžã§ã¯ã·ã§ã³ãªã©ã®äžè¬ç㪠Web ããŒã¹ã®æ»æããä¿è·ããå¿ èŠããããŸããããã«ãé©åãªå ¥åæ€èšŒãšãµãã¿ã€ãºãå®è¡ããå®å šãªãšã©ãŒåŠçã¡ã«ããºã ãå®è£ ãããã¹ãŠã®ãµãŒãããŒã㣠ã©ã€ãã©ãªãææ°ã®ç¶æ ã«ä¿ã€å¿ èŠããããŸãã
ããŒã¿ ãã©ã€ãã·ãŒã¯ãç¹ã«æ©å¯æ§ã®é«ããŠãŒã¶ãŒ ããŒã¿ãæ±ãå Žåããã©ã°ã€ã³ ã»ãã¥ãªãã£ã®ãã 1 ã€ã®éèŠãªåŽé¢ã§ããéçºè ã¯ããŒã¿æå°åã®ååãéµå®ãããã©ã°ã€ã³ãæ©èœããããã«å¿ èŠãªããŒã¿ã®ã¿ãåéããå¿ èŠããããŸããããã«ã転éäžã®ããŒã¿ãšä¿åäžã®ããŒã¿ã®äž¡æ¹ã«æå·åãæ¡çšããæš©éã®ãªãå人ãããŒã¿ãååãããã¢ã¯ã»ã¹ãããã§ããªãããã«ããå¿ èŠããããŸãã
ä»ã®ã·ã¹ãã ããµãŒãã¹ãšã®çµ±åã«ãããã»ãã¥ãªãã£äžã®è匱æ§ãçºçããå¯èœæ§ãããã«é«ãŸããŸããéçºè ã¯ãå®å šãªèªèšŒããã³èªå¯ã¡ã«ããºã ãçµã¿èŸŒãã§ãèš±å¯ããããŠãŒã¶ãŒã®ã¿ããã©ã°ã€ã³ã®æ©èœãšãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ããå¿ èŠããããŸãããã®åé¡ã«å¯Ÿãã 1 ã€ã®è§£æ±ºçã¯ãAPI éä¿¡ãä¿è·ããããã«åºãæ¡çšãããŠãããã¬ãŒã ã¯ãŒã¯ã§ãã OAuth 2.0 ãŸã㯠OpenID Connect ã®ãµããŒããå®è£ ããããšã§ãã
éçºè ã®æåã®åªåã«ãããããããç¹ã«é²åãç¶ãããµã€ããŒè åšã®ç¶æ³ãèæ ®ãããšãã»ãã¥ãªãã£ã®è匱æ§ãå®å šã«å ãããã©ã°ã€ã³ãæ¡åŒµæ©èœã¯ãããŸããããããã£ãŠãå ç¢ãªããã管çããã»ã¹ãå®è£ ããããšãéèŠã§ããéçºè ã¯ãã©ã°ã€ã³ã®æœåšçãªã»ãã¥ãªãã£åé¡ãç¶ç¶çã«ç£èŠããå¿ èŠã«å¿ããŠã¢ããããŒããããããéããã«ãªãªãŒã¹ããå¿ èŠããããŸãããšã³ããŠãŒã¶ãŒããã»ãã¥ãªãã£ãç¶æããããã«ãããã®æŽæ°ãç±å¿ã«é©çšããå¿ èŠããããŸãã
ãã©ã°ã€ã³ã®ã»ãã¥ãªãã£ãããã«åŒ·åããããã«ãéçºè ã¯åŸ¹åºçãªã³ãŒã ã¬ãã¥ãŒãšå®æçãªã»ãã¥ãªãã£ç£æ»ã«åãçµãããšãæšå¥šãããŸããååãå€éšã®å°éå®¶ã«ã³ãŒããã¬ãã¥ãŒããŠããããšãéçºããã»ã¹äžã«èŠèœãšãããå¯èœæ§ã®ããæœåšçãªã»ãã¥ãªãã£è匱æ§ãç¹å®ããã®ã«åœ¹ç«ã¡ãŸããããã«ãèªåã¹ãã£ã³ããã³ãã¹ã ããŒã«ã掻çšãããšãéçã³ãŒãåæãšåçã©ã³ã¿ã€ã åæã®äž¡æ¹ã®èгç¹ããããã©ã°ã€ã³ ã³ãŒãããŒã¹ã®è匱æ§ã®æ€åºã«åœ¹ç«ã¡ãŸãã
ãŸããéçºããŒã å ã§ã»ãã¥ãªãã£ã«å¯Ÿããèãæ¹ãå¹ããã³ãŒãã£ã³ã°ã«å¯Ÿããã»ãã¥ãªãã£ç¬¬äžã®ã¢ãããŒãã®éèŠæ§ã匷調ããããšãéèŠã§ããããã¯ã宿çãªãã¬ãŒãã³ã° ã»ãã·ã§ã³ãã¯ãŒã¯ã·ã§ãããç¥èå ±æã®åãçµã¿ãéããŠå®çŸã§ããéçºè ããµã€ããŒã»ãã¥ãªãã£ã®ææ°ãã¬ã³ããåžžã«ææ¡ã§ããããã«ä¿ããŸãã
çµè«ãšããŠããã©ã°ã€ã³ã®ã»ãã¥ãªãã£ã¯ããã©ã°ã€ã³ãšæ¡åŒµæ©èœã®éçºåéã«ãããŠãéçºè ãšãŠãŒã¶ãŒã®äž¡æ¹ã«ãšã£ãŠéèŠãªæžå¿µäºé ã§ããå®å šãªã³ãŒãã£ã³ã°æ £è¡ãéµå®ããå ç¢ãªèªèšŒã¡ã«ããºã ãçµã¿èŸŒã¿ãããŒã¿ ãã©ã€ãã·ãŒã確ââä¿ããç¶ç¶çãªããã管çãšã»ãã¥ãªãã£ç£æ»ã«åžžã«æ³šæãæãããšã§ãéçºè ã¯æœåšçãªã»ãã¥ãªãã£è åšããäœåãšãŠãŒã¶ãŒãä¿è·ããããšã«åãçµãããšãã§ããŸãã AppMasterã§ã¯ããã©ã°ã€ã³ã®ã»ãã¥ãªãã£ã®éèŠæ§ãçè§£ããŠãããåœç€Ÿã®no-codeãã©ãããã©ãŒã ã¯ãäŒæ¥ãšå人ã®éçºè ã®äž¡æ¹ãé«å質ã§å®å šãã€ã¹ã±ãŒã©ãã«ãªãœãããŠã§ã¢ ãœãªã¥ãŒã·ã§ã³ãç°¡åã«äœæã§ããããã«æ¯æŽããŸãã