<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prevent javascript execution to users in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-javascript-execution-to-users/m-p/270409#M35757</link>
    <description>&lt;P&gt;Hi Dynatrace community,&lt;/P&gt;
&lt;P&gt;Is there a way to prevent users to execute javascript in apps? i.e Dashboards, workflows, notebooks etc...&lt;/P&gt;
&lt;P&gt;The use case here is, we would need to prevent an user to create a javascript tile in the mentioned apps (to avoid malicious intents). Is there a permission in the policies for this?&lt;/P&gt;
&lt;P&gt;The second use case is, can we prevent users to create a javascript tile but they can consume a dashboard/notebook/workflow that an user with elevated permissions have created?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Paco&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2025 07:09:44 GMT</pubDate>
    <dc:creator>paco_castillo</dc:creator>
    <dc:date>2025-02-20T07:09:44Z</dc:date>
    <item>
      <title>Prevent javascript execution to users</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-javascript-execution-to-users/m-p/270409#M35757</link>
      <description>&lt;P&gt;Hi Dynatrace community,&lt;/P&gt;
&lt;P&gt;Is there a way to prevent users to execute javascript in apps? i.e Dashboards, workflows, notebooks etc...&lt;/P&gt;
&lt;P&gt;The use case here is, we would need to prevent an user to create a javascript tile in the mentioned apps (to avoid malicious intents). Is there a permission in the policies for this?&lt;/P&gt;
&lt;P&gt;The second use case is, can we prevent users to create a javascript tile but they can consume a dashboard/notebook/workflow that an user with elevated permissions have created?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Paco&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 07:09:44 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-javascript-execution-to-users/m-p/270409#M35757</guid>
      <dc:creator>paco_castillo</dc:creator>
      <dc:date>2025-02-20T07:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent javascript execution to users</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-javascript-execution-to-users/m-p/270564#M35773</link>
      <description>&lt;P&gt;Hi Paco,&lt;/P&gt;&lt;P&gt;I think you can define a read-only IAM policy to the objects you need to.&lt;BR /&gt;Ex.:&lt;BR /&gt;ALLOW settings:objects:read, settings:schemas:read WHERE settings:schemaId IN ("builtin:dashboards.general","builtin:dashboards.presets","builtin:dashboards.image.allowlist");&lt;BR /&gt;ALLOW automation:workflows:read&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, someone may propose a more complete solution than mine.&lt;BR /&gt;Hope it helps anyway.&lt;BR /&gt;Regards,&lt;BR /&gt;Elena.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 15:00:29 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-javascript-execution-to-users/m-p/270564#M35773</guid>
      <dc:creator>erh_inetum</dc:creator>
      <dc:date>2025-02-20T15:00:29Z</dc:date>
    </item>
  </channel>
</rss>

