Skip to Main Content
Merative Ideas Portal

Shape the future of Merative!

We invite you to shape the future of Merative, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Post your ideas

Start by posting ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the Merative team to refine your idea

Help Merative prioritize your ideas and requests

The Merative team may need your help to refine the ideas so they may ask for more information or feedback. The offering manager team will then decide if they can begin working on your idea. If they can start during the next development cycle, they will put the idea on the priority list. Each team at Merative works on a different schedule, where some ideas can be implemented right away, others may be placed on a different schedule.

Receive notification on the decision

Some ideas can be implemented at Merative, while others may not fit within the development plans for the product. In either case, the team will let you know as soon as possible. In some cases, we may be able to find alternatives for ideas which cannot be implemented in a reasonable time.


Merative External Privacy Statement: https://www.merative.com/privacy

Status Future consideration
Created by Garry Heap
Created on Feb 13, 2020

Additional hook point needed to customize OnlineSecurityImplementation.checkParticipantSecurity

https://www-01.ibm.com/support/entdocview.wss?uid=swg1PO02157 was provided to give a hook point, but it is only called once if caching is enabled (as it should be for performance). We need a more flexible hook point as part of checkParticipantSecurity() that is called every time.
Alternatively, SecurityImplementationFactory should be able to inject custom version of OnlineSecurityImplementation)

Customer Name Scottish Government
  • Attach files
  • Guest
    Reply
    |
    Aug 27, 2020

    Adding my voice for this - this is also something I've seen on the vast majority of projects I've worked on over the last 16 years and should not be difficult for IBM to provide a hook point to allow projects to implement this.

  • Guest
    Reply
    |
    Apr 15, 2020

    Hi Garry,

    We acknowledge that this enhancement request has been accepted for consideration. It may not be delivered within the release currently under development however the theme is aligned with our current multi-year strategy and will be considered for a future release.

    The final solution regarding the requirement of the "need to do something ('audit'/log etc) for every single call" may be implemented in a different fashion than the one suggested in this request.

    IBM may consider and evaluate any RFE Community feedback for this request through activities such as voting.

    IBM will update this request in the future.

    Thank you for your interest in the Cúram product.
    Shane McFadden, Cúram SPM Product Management team

  • Garry Heap
    Reply
    |
    Apr 7, 2020

    quick comment, this is a common requirement in other curam projects that i've seen also need to do something ('audit'/log etc) for every single call - so either need to enable operation level auditing for ALL operations, or do a single customization in OnlineSecurityImplementation

  • Guest
    Reply
    |
    Apr 6, 2020

    Hi Garry,

    In order to evaluate your request, we require that you provide more detail so that we can fully understand your requirements.

    In particular regarding this statement: "We have a requirement to call an external REST API for every page access, for audit purposes."

    Can we get some more details on what the customer needs to audit here, even from a generic viewpoint? There are existing auditing capabilities within the SPM product already so we would like to understand the customer requirements and hence why they cannot use the existing auditing capability within SPM for their purposes as described here:
    https://www.ibm.com/support/knowledgecenter/SS8S5A_7.0.10/com.ibm.curam.content.doc/ServerDeveloper/r_SERDEV_Configuration7Audit1.html

    Thank you,
    Shane McFadden, Cúram SPM Product Management team

  • Guest
    Reply
    |
    Feb 14, 2020

    Hi Garry,

    Thank you for your enhancement request.
    We require some further analysis to determine whether or not this enhancement can be considered in a future release.
    I will provide another response when our investigation is complete.

    Thank you,
    Shane McFadden, Cúram SPM Product Management team