This is an IBM Automation portal for Digital Business Automation products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Cloud Pak for Business Automation - including Business Automation Studio and App Designer, Business Automation Insights
Business Automation Workflow (BAW) - including BAW, Business Process Manager, Workstream Services, Business Performance Center, Advanced Case Management
Content Services - FileNet Content Manager
Content Services - Content Manager OnDemand
Content Services - Daeja Virtual Viewer
Content Services - Navigator
Content Services - Content Collector for Email, Sharepoint, Files
Content Services - Content Collector for SAP
Content Services - Enterprise Records
Content Services - Content Manager (CM8)
Datacap
Automation Document Processing
Automation Decision Services (ADS)
Operational Decision Manager
Robotic Process Automation
Robotic Process Automation with Automation Anywhere
Blueworks Live
Business Automation Manager Open Edition
IBM Process Mining
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
See this idea on ideas.ibm.com
The read-only setting for case properties in the Case client UI (runtime) is applied only at the view level and does not enforce restrictions at the backend Case Manager REST API level.
The CaseManager API and CaseClient plugin service are designed to save any case properties, regardless of their read-only status in the client view. This means if an intruder manipulates the property value via the plugin service or a REST request, it will be processed as per the current design.
Idea priority | Urgent |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Hi Dave,
Can you please provide some document around "map the values to temporary variables before binding those into the UI elements"
Also, regarding "User level assess security", in our case same user can be Worker(write access) or Approver (read access, but can take action on case i.e. can approve/reject the case).
In a screenshare with L2, we assign property template to read only in CPE but that also able to updated from brup penetration tool.
Thanks
The case/process data model and the UIs you build that sit on top are not directly related. When building yoru UIs using client-side human services, you specify what data from the server is passed into the UI layer, and from there, you can control how that data is bound to UI elements such as edit boxes and controls. If you have case/process data that you want to ensure does not get updated back on the server, even by a malicious attempt by an end user hacking in their browser debugger to remove a "read only" property, you can map the values to temporary variables before binding those into the UI elements.
User level assess security for case objects can also be applied at the CPE server level.
Hello.
Are you referring to setting the r/o attribute on the UI view in the page designer?
This is really crucial to be addressed as the client gets their AVA performed from third party vendor who use to intercept the request using their tools to manipulate the values which should be edit restricted.