Dear
ManageEngine Support Team,
We are
currently using ServiceDesk Plus version 15.2. As
part of our security enhancement efforts, we have identified a need to
automatically sanitize (neutralize) hyperlinks that come from end‑users in
incoming tickets, replies, and other emails within the ITSM system.
Our
specific requirement is as follows:
- When a user submits a link that
points to a domain not on our trusted (whitelisted) list
(i.e., our internal domains or approved partner domains), that link should
be rendered as plain text (e.g., the <a> tag
removed, or the URL displayed without clickable behaviour).
- Links to our own or trusted
domains should remain fully clickable and unchanged.
We have
reviewed the available documentation for our version but could not find any
built‑in feature that performs such selective link sanitisation on incoming user
content. Therefore, we kindly ask for your assistance with the following
questions:
- Does ServiceDesk Plus version
15.2 offer any native functionality (even a hidden
configuration setting or security module) to automatically sanitise
incoming links based on a whitelist of trusted domains?
- If such a feature does not
exist, is there any supported way to implement this behaviour using custom
scripts, business rules, or event handlers that would process incoming
emails and comments before they are stored or displayed
in the UI? If so, could you provide a brief example or guidance?
- Are there any plans to
introduce similar functionality in upcoming releases?
- If none of the above options
are feasible, what alternative approach would you recommend to achieve our
goal (e.g., using APIs, webhooks, custom plugins, or an external proxy for
incoming traffic)?
We would
greatly appreciate any information or suggestions you can provide. If you need
additional details about our environment or use case, please let us know, and
we will be happy to supply them.
Thank you
for your time and support.
Regards,
Dmitriy