Non-Requestable entitlement is requestable via API

ejeong
All-Star
All-Star

We restricted requestable entitlement by adding query under entitlement type. 

But we found that this entitlement is reqeustable via API. Is this something expected? 

If we apply access query in endpoint, I remember API returned error when trying to make reqeust for that endpoint.

8 REPLIES 8

rushikeshvartak
All-Star
All-Star

which api are you using

{{url}}/ECM/{{path}}/createrequest

Are you able to submit request for same.

No,,, I can't see the entitlement as it's hidden for that user...

Then its working as expected 

hmm. as that entitlement is not requestable from UI by reqeustable ent query. I am expecting it's not requestable via API as well.

entitlement_value 1480 is not showing from UI by requestable ent config

ejeong_0-1675145064515.png

But it was successful from API. 

ejeong_1-1675145104404.png

 

 

Missing validation. raise saviynt freshdesk ticket. I will test in latest version tomorrow and keep you posted