New [HTML] Datatype ACL in Zurich

Anthony_Pecora
Tera Contributor

Hi everyone,

While performing testing for our upgrade to Zurich, we have discovered a new ACL from Zurich that is causing issues on our forms that have HTML-type fields. This ACL is restricting access to the HTML type fields to users who have the new "snc_required_script_writer_permission" role that is controlled via the new Scripting Governance Tool. A few examples fields we have found being impacted are:

 

Demand/Project (dmn_demand/pm_project):

  • Business Case
  • Risk of Performing
  • Risk of not performing
  • Enablers
  • Barriers
  • In scope
  • Out of scope
  • Assumptions

Problem (problem):

  • Workaround
  • Cause Notes
  • Fix Notes

Story (rm_story):

  • Acceptance Criteria

 

Important Points:

  • This new datatype ACL is a read-only ACL and we cannot modify or deactivate it.
  • We have also tried making a new allow-if datatype (HTML) ACL to mask this, but this solution did not work.
  • It seems the only way to allow users to have access to these fields (many of them being OOB) would be to provide users with the new “snc_required_script_writer_permission” role which is described as the prerequisite to allow users to write scripts on the instance.
    • It is unreasonable to provide this scripting role to non-scripting users such as demand/project managers, problem managers, and other itil users for them to simply have access to HTML type fields.

 

Has anyone else experienced this issue or found a workaround for this other than providing the scripting access role to non-scripting users?

9 REPLIES 9

Brenda Williams
Tera Contributor

Haven't started the upgrade yet but are knowledge articles impacted?

They are.

AdamEndwright
Tera Contributor

We have the same issue.  I didn't notice until we ran the Scripting Governance Tool and removed most users from the Conditional Script Writer group.  My only solution for now is to add them back.  I don't really want that because many users need to edit HTML fields, but very few need any scripting ability.

You can create ACL for same field on table level. example you have HTML field on PRB then create new acl for that field/  operation as write decision type as deny unless and add role. example. This will give them access back to HTML field