Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
Previously, in the case of entity reference, the check if the entity was managed (reminder, we exclude users and config entities from sharing) was done on the JSON returned by the JSON API.