UI Policy rules

The below table shows the list of ServiceNow UI policy rules that are checked by Quality Clouds.

Description

Severity

Area of impact

Possible use of private data - UI Policy scriptFalseWarningSecurity
Possible use of private data - UI Policy scriptTrueWarningSecurity
JavaScript - Avoid use of Function Constructors - UI Policy scriptFalseHighSecurity
JavaScript - Avoid use of Function Constructors - UI Policy scriptTrueHighSecurity
JavaScript - Avoid making connections on unsafe protocols - UI Policy scriptFalseWarningSecurity
JavaScript - Avoid making connections on unsafe protocols - UI Policy scriptTrueWarningSecurity
JavaScript - Optimize Loops - UI Policy scriptFalseWarningPerformance
JavaScript - Optimize Loops - UI Policy scriptTrueWarningPerformance
JavaScript - Avoid unrestricted targetOrigin on cross-domain messaging - UI Policy scriptFalseHighSecurity
JavaScript - Avoid unrestricted targetOrigin on cross-domain messaging - UI Policy scriptTrueHighSecurity
JavaScript - Avoid use of debugger statements - UI Policy scriptFalseHighSecurity
JavaScript - Avoid use of debugger statements - UI Policy scriptTrueHighSecurity
JavaScript - Avoid use of WebDB - UI Policy scriptFalseHighSecurity
JavaScript - Avoid use of WebDB - UI Policy scriptTrueHighSecurity
JavaScript - Use === comparison - UI Policy scriptFalseWarningManageability
JavaScript - Use === comparison - UI Policy scriptTrueWarningManageability
Synchronous AJAX call in UI Policies - scriptFalseHighPerformance
Synchronous AJAX call in UI Policies - scriptTrueHighPerformance
UI Policies using GlideRecord - scriptFalseHighPerformance
UI Policies using GlideRecord - scriptTrueHighPerformance
UI Policies with hard-coded sys_ids - scriptFalseMediumManageability
UI Policies with hard-coded sys_ids - scriptTrueMediumManageability
Document Object Model (DOM) manipulation in UI Policies - scriptFalseHighManageability
Document Object Model (DOM) manipulation in UI Policies - scriptTrueHighManageability
Modified Out of the Box ElementWarningScalability
Dot walking to sys_id - UI Policy scriptTrueMediumPerformance
Dot walking to sys_id - UI Policy scriptFalseMediumPerformance
Usage of g_form.setValue on a reference field without displayValue - UI Policy scriptTrueHighPerformance
Usage of g_form.setValue on a reference field without displayValue - UI Policy scriptFalseHighPerformance




Last modified on Mar 25, 2021