ANS-1415 · SUITESCRIPT DEVELOPMENT
How to Search for Roles Assigned to NetSuite Script Deployments?
Understand how to programmatically retrieve role assignments for script deployments, including those not directly searchable via standard methods.
Short answer
To find roles assigned to NetSuite script deployments, including those in unsearchable fields, a SuiteScript search can be executed. This involves creating a script deployment search, iterating through results, and loading each deployment record to extract 'allroles' or 'audslctrole' field values, then logging the associated script name and roles.
Scenario
NetSuite administrators and developers often need to identify which roles are associated with specific script deployments. Standard searches may not directly expose all role assignments, particularly for fields that are not searchable. This can make it challenging to audit or manage script access permissions effectively.
Solution
To programmatically retrieve role assignments for script deployments, including those in unsearchable fields, a SuiteScript search can be performed. The following generic code snippet can be executed in the browser console or as part of a SuiteScript to load each script deployment and check its associated roles:
/*n* This code snippet is designed to load each script deployment so we mayn* check unsearchable fields, such as roles.n*/nn//Add filters and columns if necessary. Search works on internalid, so notn//necessary if not needed.nvar filters = [];nnvar columns = [];nn//Create searchnvar deploymentSearch = searchModule.create({ntype: searchModule.Type.SCRIPT_DEPLOYMENT,nfilters: filters,ncolumns: columnsn});nnvar deploymentResults = deploymentSearch.run();nvar deploymentIds = [];nndeploymentResults.each(function (row){//10 GovernancendeploymentIds.push(row.id);n//*** PUT HANDLING HERE ***//nvar deploymentRecord = recordModule.load({ //5 Governance (because notntransaction record or custom record)ntype: recordModule.Type.SCRIPT_DEPLOYMENT,nid: row.idn});nvar scriptName = deploymentRecord.getText({
fieldId:'script'
});nvar allRoles = deploymentRecord.getValue({
fieldId: 'allroles'
});nif(allRoles){
console.log('*** ' + scriptName + ' / ' + row.id + ' ***');nconsole.log(" -> ALL ROLES");n}else{
//For manually selected rolesnvar allRoles = deploymentRecord.getValue({
fieldId: 'audslctrole'
});nconsole.log('*** ' + scriptName + ' / ' + row.id + ' ***');nif(allRoles){
console.log(allRoles);n}else{
console.log(' -> ' + deploymentRecord.getText({fieldId: 'status'}));
}
}nreturn true;n});This script iterates through each script deployment, loads its record, and checks the allroles field. If allroles is false, it then checks the audslctrole field for manually selected roles. The script logs the script name, deployment ID, and the assigned roles or status. Users should be aware of the NetSuite governance limits when running such searches, as each record load consumes governance units.
Expert NetSuite Support
Need help with this NetSuite issue?
SuiteScript Development consulting and configuration support
