Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Catalog Item Visibility Based on Dynamic Role Pattern (x_*) Without User Criteria

YerragondaA3099
Tera Contributor

Hi Community,

I have a requirement where a specific Catalog Item should be visible only to:

  • Users with the itil role, or
  • Users who have any role that starts with x_

Normally, I would implement this using User Criteria, but in our instance the system property glide.sc.use_user_criteria is disabled due to other business requirements, so User Criteria is not an option.

There are over 200 roles that begin with x_

What would be the best approach to achieve this requirement for a single Catalog Item?

Thanks

@Ankur Bawiskar @Dr Atul - LNG @Allen Andreas @Hardit Singh 
1 ACCEPTED SOLUTION

Ankur Bawiskar
Tera Patron

@YerragondaA3099 

then you can use onLoad catalog client script + GlideAjax

the script include would validate if logged in user has itil role or has any role starts with x_

if not then it shows an alert to user and directly takes user to portal homepage

💡 If my response helped, please mark it as correct ✅ and close the thread 🔒— this helps future readers find the solution faster! 🙏

Regards,
Ankur
✨ Certified Technical Architect  ||  ✨ 10x ServiceNow MVP  ||  ✨ ServiceNow Community Leader

View solution in original post

8 REPLIES 8

Ankur Bawiskar
Tera Patron

@YerragondaA3099 

then you can use onLoad catalog client script + GlideAjax

the script include would validate if logged in user has itil role or has any role starts with x_

if not then it shows an alert to user and directly takes user to portal homepage

💡 If my response helped, please mark it as correct ✅ and close the thread 🔒— this helps future readers find the solution faster! 🙏

Regards,
Ankur
✨ Certified Technical Architect  ||  ✨ 10x ServiceNow MVP  ||  ✨ ServiceNow Community Leader

musislam
Kilo Sage

@YerragondaA3099 since glide.sc.use_user_criteria is off, the item should still honour the older availability fields on sc_cat_item, and that's where I'd do it rather than client side. A client script redirect still leaves the item visible in the catalog and search, and it only gets checked in the browser.

Listing 200+ x_ roles in the Roles field isn't practical, but the Entitlement script field on the item takes a script that returns true/false. Something like checking gs.hasRole('itil'), and if that fails, looking up sys_user_has_role for the user where role.name STARTSWITH x_. If the field isn't on your form, add it through Form Layout.

I haven't confirmed this on your release, so a couple of questions first:
1. Is this in Service Portal, native UI, or both?
2. Does the item currently have anything in the Roles field?

If that works for you, mind marking it as the recommended solution? Helps me support these better for the community.

Macki | Deloitte AU | Engineer Lead

Aditya_hublikar
Giga Sage

Hello @YerragondaA3099 ,

 

As per my understanding without user criteria you can not directly hide catalog item from users . You can try approach suggested by @Ankur Bawiskar  . By this approach user can see catalog item but will not able to access cat item .

 

If this helps you then mark it as helpful and accept as solution.

Regards,

Aditya

Allen Andreas
Tera Patron

Hi  @YerragondaA3099 

That's interesting that that system property is disabled, but I can understand if there's some sort of business requirement resulting in that choice.

 

In any case, it sounds like you would have to hide the catalog item in a similar fashion using a "query business rule", instead. This would hide it from any sort of catalog item list, widget list, etc. This would need to be built to check if the catalog item is x and if so, check their roles (could use gs.getSession().getRoles() - which returns a comma separated list of all their roles) and if in that list, they don't have ITIL or anything with "x_", then you remove filter out that catalog item.

 

Additionally, you may want to also consider creating an read ACL on the "sc_cat_item" table to also limit who can see this, as an extra step.

 

Ideally though, you all would use user criteria, and not have to implement the same sort of mechanisms in a custom fashion with just introduces more and more tech debt.


Please consider marking my reply as Helpful and/or Accept Solution, if applicable. Thanks!