Sanitizing Incoming Links in ServiceDesk Plus

Sanitizing Incoming Links in ServiceDesk Plus

Dear ManageEngine Support Team,

We are currently using ServiceDesk Plus version 15.2. As part of our security enhancement efforts, we have identified a need to automatically sanitize (neutralize) hyperlinks that come from end‑users in incoming tickets, replies, and other emails within the ITSM system.

Our specific requirement is as follows:

  • When a user submits a link that points to a domain not on our trusted (whitelisted) list (i.e., our internal domains or approved partner domains), that link should be rendered as plain text (e.g., the <a> tag removed, or the URL displayed without clickable behaviour).
  • Links to our own or trusted domains should remain fully clickable and unchanged.

We have reviewed the available documentation for our version but could not find any built‑in feature that performs such selective link sanitisation on incoming user content. Therefore, we kindly ask for your assistance with the following questions:

  1. Does ServiceDesk Plus version 15.2 offer any native functionality (even a hidden configuration setting or security module) to automatically sanitise incoming links based on a whitelist of trusted domains?
  2. If such a feature does not exist, is there any supported way to implement this behaviour using custom scripts, business rules, or event handlers that would process incoming emails and comments before they are stored or displayed in the UI? If so, could you provide a brief example or guidance?
  3. Are there any plans to introduce similar functionality in upcoming releases?
  4. If none of the above options are feasible, what alternative approach would you recommend to achieve our goal (e.g., using APIs, webhooks, custom plugins, or an external proxy for incoming traffic)?

We would greatly appreciate any information or suggestions you can provide. If you need additional details about our environment or use case, please let us know, and we will be happy to supply them.

Thank you for your time and support.


Regards,
Dmitriy