Scripted REST API Permissions

AmolJ
Tera Expert

I am on Zurich.

I have instance "A" and on this instance I have a user account marked as both "machine" and Internal Integration User. This user account is linked to a role which is linked to a REST API's "execute" ACL.

This ACL is linked to a scripted REST API with 2 resources. One of the resources is a POST resource used by another ServiceNow instance (instance B) to create incidents into this instance.

Neither this user through a directly assigned role, nor through a role contained by the ACL role can this user create incidents.

Yet when from instance B I post, it creates incident on instance A.

I have used GlideRecordSecure on instance A in the POST resource.

Any hints?

0 REPLIES 0