Using Power Automate/webhooks securely on public surveys

512
3
02-11-2022 07:01 AM
ColinCampbell1
New Contributor III

Hi,

I'm interested in using Power Automate for a process involving Survey123, Outlook and Excel, but my survey is a public one and the guidance on public surveys highlights that webhooks for such are 'subject to potential abuse by malicious users'.

I was wondering if there was any more information on this or if there was any guidance showing you how to safely use Power Automate with public surveys (assuming you can at all).

Thanks in advance

Colin

Tags (2)
0 Kudos
3 Replies
ZacharySutherby
Esri Regular Contributor

Hello @ColinCampbell1

The alternative workflow noted in the document would be our suggested workflow. 

Thank you,
Zach
0 Kudos
TanGnar
Occasional Contributor

Another alternative workflow I'd like your input on, please. 

Could you instead set up a webhook on the protected feature layer that is not attached to the survey? You could trigger that on an added feature. Would that take away risk from a webhook on the public survey123 and accomplish the same goal? 

It does look like developing the webhook on the feature layer is a more involved process than the Survey123 webhook. 

0 Kudos
TanGnar
Occasional Contributor

I'm curious why webhooks were opened up to public surveys if they pose such a security risk, with minimal mention of the risk except buried in the somewhat obscure linked PDF. 

0 Kudos