Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

How to trigger Access Analyzer - Comparing user records through script background

UmaSaiDeeK
Mega Contributor

I would like to know the class and code details how to trigger Access Analyzer - simulators from backend scripts. I have tried below script include but couldn't figure it out...!!!

UmaSaiDeeK_0-1789818590857.png

 

8 REPLIES 8

l457
Kilo Patron

The access analyzer queries the tables for the types of records you are comparing, sys_user, sys_user_has_role or sys_user_grmember and then the comparison is done clientside. I think you might have already figured this out but nonetheless

[
  {
    "type": "GRAPHQL",
    "definitionSysId": "21f155c65310101024e5ddeeff7b1210",
    "inputValues": {
      "encodedQuery": {
        "type": "JSON_LITERAL",
        "value": "user.sys_id=62826bf03710200044e0bfc8bcbe5df1^ORuser.sys_id=0a826bf03710200044e0bfc8bcbe5d7a"
      },
      "offset": {
        "type": "JSON_LITERAL",
        "value": null
      },
      "returnFieldMetadata": {
        "type": "JSON_LITERAL",
        "value": false
      },
      "sortType": {
        "type": "JSON_LITERAL",
        "value": "asc"
      },
      "limit": {
        "type": "JSON_LITERAL",
        "value": "100000"
      },
      "orderBy": {
        "type": "JSON_LITERAL",
        "value": "role"
      },
      "returnRowCount": {
        "type": "JSON_LITERAL",
        "value": false
      },
      "returnFields": {
        "type": "JSON_LITERAL",
        "value": "user,role"
      },
      "queryCategory": {
        "type": "JSON_LITERAL",
        "value": ""
      },
      "returnTableMetadata": {
        "type": "JSON_LITERAL",
        "value": false
      },
      "table": {
        "type": "JSON_LITERAL",
        "value": "sys_user_has_role"
      }
    },
    "macroponentSysId": "b2d8fb3e77403110638cfe21fe5a99fa",
    "pipelineId": "dataSource"
  }
]

There is no complex backend logic and there aren't even records saved for these types of static comparisons. The comparison script would then essentially be diffing two arrays or objects. To use the other analyzer features programmatically you can create a script include inside the scope and extend the AccessAnalyzeExecutor script include.  To analyze create a record in the [sn_access_analyzer_request] table and call the analyze method on that record.

var a = new GlideRecord("sn_access_analyzer_request")
a.newRecord()
a.setValue("operations", "read")
a.setValue("target_table", "incident")
a.setValue("analyze_by", "User")
a.setValue("resource_type", "record")
a.setValue("target_record", "e8e875b0c0a80164009dc852b4d677d5")
a.setValue("target_field", "active")
a.setValue("analyzed_by", "User: Abel Tuter")
a.setValue("user", "62826bf03710200044e0bfc8bcbe5df1")
var action = {}
action.setRedirectURL = function () { }
new sn_access_analyzer.MyAccessAnalyzer().analyze(a, action);
var MyAccessAnalyzer = Class.create();
MyAccessAnalyzer.prototype = Object.extendsObject(AccessAnalyzeExecutor, {
	type: 'MyAccessAnalyzer'
});

 

UmaSaiDeeK
Mega Contributor
Illegal access to package_private script include MyAccessAnalyzer: caller not in scope sn_access_analyzer, Script ES Level: 0
Evaluator.evaluateString() problem: java.lang.SecurityException: Illegal access to package_private script include MyAccessAnalyzer: caller not in scope sn_access_analyzer:     com.glide.script.RhinoEnvironment.checkScriptableAccess(RhinoEnvironment.java:723)
    com.glide.script.ARhinoScope.checkScriptableAccess(ARhinoScope.java:134)
    com.glide.script.ARhinoScope.get(ARhinoScope.java:95)
    com.glide.script.RhinoScope.get(RhinoScope.java:52)
    com.glide.script.PackageScope.get(PackageScope.java:44)
    org.mozilla.javascript.ScriptableObject.getProperty(ScriptableObject.java:2401)
    org.mozilla.javascript.ScriptRuntime.getObjectProp(ScriptRuntime.java:1843)
    org.mozilla.javascript.ScriptRuntime.getObjectProp(ScriptRuntime.java:1838)
    org.mozilla.javascript.Interpreter.interpretLoop(Interpreter.java:1466)
    org.mozilla.javascript.Interpreter.interpret(Interpreter.java:940)
    org.mozilla.javascript.InterpretedFunction.lambda$call$0(InterpretedFunction.java:127)
    com.glide.caller.gen.null_null_script.call(Unknown Source)
    com.glide.script.ScriptCaller.call(ScriptCaller.java:22)
    org.mozilla.javascript.InterpretedFunction.call(InterpretedFunction.java:125)
    org.mozilla.javascript.ContextFactory.doTopCall(ContextFactory.java:722)
    org.mozilla.javascript.ScriptRuntime.doTopCall(ScriptRuntime.java:4812)
    org.mozilla.javascript.InterpretedFunction.exec(InterpretedFunction.java:141)
    com.glide.script.ScriptCompiler.executeAndPublishMetric(ScriptCompiler.java:83)
    com.glide.script.ScriptEvaluator.execute(ScriptEvaluator.java:552)
    com.glide.script.ScriptEvaluator.evaluate(ScriptEvaluator.java:254)
    com.glide.script.fencing.GlideScopedEvaluator.evaluateScript(GlideScopedEvaluator.java:439)
    com.glide.script.fencing.GlideScopedEvaluator.evaluateScript(GlideScopedEvaluator.java:311)
    com.glide.script.fencing.GlideScopedEvaluator.evaluateScript(GlideScopedEvaluator.java:288)
    com.glide.processors.ScriptProcessor.evaluateScript0(ScriptProcessor.java:411)
    com.glide.processors.ScriptProcessor.lambda$evaluateScriptWithRecordingOption$0(ScriptProcessor.java:394)
    com.glide.rollback.recording.RollbackRecorder.execute(RollbackRecorder.java:67)
    com.glide.processors.ScriptProcessor.evaluateScriptWithRecordingOption(ScriptProcessor.java:394)
    com.glide.processors.ScriptProcessor.evaluateScript(ScriptProcessor.java:375)
    com.glide.processors.ScriptProcessor.runScript(ScriptProcessor.java:272)
    com.glide.processors.ScriptProcessor.process(ScriptProcessor.java:230)
    com.glide.processors.AProcessor.runProcessor(AProcessor.java:919)
    com.glide.processors.AProcessor.processTransaction(AProcessor.java:345)
    com.glide.processors.ProcessorRegistry.process0(ProcessorRegistry.java:200)
    com.glide.processors.ProcessorRegistry.process(ProcessorRegistry.java:188)
    com.glide.ui.GlideServletTransaction.process(GlideServletTransaction.java:62)
    com.glide.sys.Transaction.run(Transaction.java:3248)
    com.glide.ui.HTTPTransaction.run(HTTPTransaction.java:44)
    com.glide.sys.util.sema.SemaphoreQueueThreadPool$Semaphore.runTransaction(SemaphoreQueueThreadPool.java:338)
    com.glide.sys.util.sema.SemaphoreQueueThreadPool$Semaphore.runThreadImpl(SemaphoreQueueThreadPool.java:303)
    com.glide.sys.util.sema.SemaphoreQueueThreadPool$Semaphore.runThread(SemaphoreQueueThreadPool.java:150)
    java.base/java.lang.Thread.run(Thread.java:841)

Background message, type:error, message: Illegal access to package_private script include

You have to make the new script include callable from global scope if you want to use it in a background script

UmaSaiDeeK
Mega Contributor

I have tried for compare 2 user accounts, and allowed accessible from all scopes still not able to get the code to call correct and get result could you please share the exact code you are using and a screenshot of the result as exactly as oob access analyzer