Configuration

Service Portal Widget requires role


Security
A01: Broken Access Control
0h 30m to fix

Why is this an issue?

To restrict access to the required audience, all service portal widgets must have a specific role defined at the widget level.

Best practices

Define roles on the service portal widget. To do so, follow the steps:

  1. Type sp_widget.list on the FIlter Navigator
  2. Search for the widget that does not have a role assigned
  3. Add the accountable role to the service portal widget and Save.
UI Pages made public
It must be a specific integration user who replaces the default admin user

© Copyright 2025. All rights reserved.