Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Catalog Item Visibility Based on Dynamic Role Pattern (x_*) Without User Criteria

YerragondaA3099
Tera Contributor

Hi Community,

I have a requirement where a specific Catalog Item should be visible only to:

  • Users with the itil role, or
  • Users who have any role that starts with x_

Normally, I would implement this using User Criteria, but in our instance the system property glide.sc.use_user_criteria is disabled due to other business requirements, so User Criteria is not an option.

There are over 200 roles that begin with x_

What would be the best approach to achieve this requirement for a single Catalog Item?

Thanks

@Ankur Bawiskar @Dr Atul - LNG @Allen Andreas @Hardit Singh 
1 ACCEPTED SOLUTION

Ankur Bawiskar
Tera Patron

@YerragondaA3099 

then you can use onLoad catalog client script + GlideAjax

the script include would validate if logged in user has itil role or has any role starts with x_

if not then it shows an alert to user and directly takes user to portal homepage

💡 If my response helped, please mark it as correct ✅ and close the thread 🔒— this helps future readers find the solution faster! 🙏

Regards,
Ankur
✨ Certified Technical Architect  ||  ✨ 10x ServiceNow MVP  ||  ✨ ServiceNow Community Leader

View solution in original post

8 REPLIES 8

Vishal Jaswal
Tera Sage

Hello @YerragondaA3099 

I believe only for such scenarios, ServiceNow has out-of-the-box "Entitlement script" field available for "Catalog items" (you can use configure form layout to show it in the catalog item / maintain item /sc_cat_item form) or use the list view: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0685499 

With entitlement script, you can make the catalog item available for or not available for to logged in user(s). As per your scenario, if logged in user has role which starts with "x_" and/or "itil", then use below code in the Entitlement script of your catalog item, impersonate that user and validate it:

var roles = gs.getUser().getRoles().toString();
var hasItilRole = /(^|,)itil(,|$)/.test(roles);
var hasXRole = /(^|,)x_[^,]*/.test(roles);
answer = hasItilRole || hasXRole;


NOTE: (^|,) means Beginning of string or comma because user may have multiple roles and (,|$) means exact text

VishalJaswal_0-1790004737172.png

Validation Results:

Before:

VishalJaswal_3-1790004809654.png

 



VishalJaswal_2-1790004790257.png

 

 

After:

VishalJaswal_4-1790004958025.png

 

 

VishalJaswal_5-1790004994597.png

 


 


Hope that helps!

I like this option! 😀


Please consider marking my reply as Helpful and/or Accept Solution, if applicable. Thanks!

YerragondaA3099
Tera Contributor

Hi @Vishal Jaswal ,

Thanks for the response

YerragondaA3099_0-1790056137215.png

 

YerragondaA3099_1-1790056156471.png

YerragondaA3099_2-1790056184196.png

 

I initially tested by keeping the Entitlement Script toggle disabled, and then enabled the Entitlement Script toggle with the following logic. However, even for a user who does not have the itil role and does not have any role starting with x_, the catalog item is still visible.

Could you please check and advise if there is any additional configuration required for the Entitlement Script to be enforced?

@YerragondaA3099 

Only visible to those who have 'itil' role or role(s) starting with 'x_'

var roles = gs.getUser().getRoles().toString();
var hasItilRole = /(^|,)itil(,|$)/.test(roles);
var hasXRole = /(^|,)x_[^,]*/.test(roles);
answer = hasItilRole || hasXRole;

 


Hope that helps!