Restrict Access to @AuraEnabled Apex Methods for Guest and Portal Users Based on User Profile (Critical Update)

This critical update gives you more control over which guest, portal, or community users can access Apex classes containing @AuraEnabled methods.

Where: This change applies to Aura and Lightning web components in Lightning communities, portals, and Salesforce Sites.

When: Salesforce will automatically activate this critical update on the auto-activation date listed on the Critical Updates page in Setup.

Why: When this critical update is activated, a guest, portal, or community user can access an @AuraEnabled Apex method only when the user’s profile allows access to the Apex class. This critical update enforces user profile restrictions for Apex classes used by Aura and Lightning web components.

How: To test this critical update, we recommend working in a sandbox.

  1. From Setup, enter Critical Updates in the Quick Find box.
  2. Select Critical Updates.
  3. Review the details for the “Restrict Access to @AuraEnabled Apex Methods for Guest and Portal Users Based on User Profile” critical update.
  4. Click Activate.
  5. Test that custom Aura or Lightning web components that you’ve developed are working correctly for guest, portal, and community users.