Book Image

Mastering ServiceNow - Second Edition

Book Image

Mastering ServiceNow - Second Edition

Overview of this book

ServiceNow is a SaaS application that provides workflow form-based applications. It is an ideal platform for creating enterprise-level applications giving requesters and fulfillers improved visibility and access to a process. ServiceNow-based applications often replace email by providing a better way to get work done. The book steps through the main aspects of the ServiceNow platform, from the ground up. It starts by exploring the core architecture of ServiceNow, including building the right data structure. To add business logic and control data, and interactivity to user interaction, you will be shown how to code on both server and the client. You will then learn more about the power of tasks, events and notifications. The book will then focus on using web services and other mechanisms to integrate ServiceNow with other systems. Furthermore, you will learn how to secure applications and data, and understand how ServiceNow performs logging and error reporting. You will then be shown how to package your applications and changes, so they can be installed elsewhere and ways to maintain them easily. If you wish to create an alternative simple interface, then explore ways to make ServiceNow beautiful using Service Portal. By the end of the book, you will know the fundamentals of the ServiceNow platform, helping you be a better ServiceNow System Administrator or developer.
Table of Contents (18 chapters)
Mastering ServiceNow Second Edition
Credits
Notice
About the Author
About the Reviewer
www.PacktPub.com
Preface

Authenticating and securing web services


Communication with a ServiceNow instance has two basic starting points:

  • It happens over HTTPS. This provides encryption for all the communication and helps prevent man-in-the-middle attacks.

  • Authentication is almost always required, usually in the form of a username and password. This ensures that the instance knows who you are.

  • Authorization is then applied. Using Security Rules and other mechanisms, the instance can decide if you are entitled to carry out a particular action.

Note

This section focuses on machine-to-machine authentication. The next chapter, explores authorization in much more detail.

Inbound authentication

When systems want to connect to ServiceNow, the most obvious and common way of authenticating is through a username and password. HTTP Basic Authentication asks that a client send these encoded details in the headers of an HTTP request.

Tip

The header for basic authentication is Authorization: Basic username:password,with the username and...