Securing webforJ Routes Before the View Exists

Broken access control has sat at the top of the OWASP Top 10 since 2021, and the 2025 list keeps it there. One of OWASP's own example scenarios is an app that keeps all its access control in the front end, where the attacker can't click through to the admin page because the JavaScript won't let them, so they skip the browser and request the URL with curl instead.
Here's a version of that you've probably written:
if (isAdmin) {
Button delete = new Button("Delete user");
delete.onClick(e -> userService.delete(selected));
self.add(delete);
}
Ordinary users don't see the button. That feels like enough, and in a server-driven framework it feels like more than enough, because the business logic is all sitting safely in Java. This post is about what actually protects that handler, what webforJ gives you for free, and where the line between the two falls.





