IBM Sterling Ideas

formerly Watson Supply Chain

Submit new product ideas for IBM Sterling solutions. Before you submit, please review existing ideas; if an idea close to yours already exists, it's better to add comments or vote on the existing idea. We will review your ideas and use them to help prioritize our product development. Best of all, the portal will automatically update you when the status of your idea has been changed. Order Management, Store Engagement, Watson Order Optimizer, Inventory Visibility, CPQ and Call Center are now part of Watson Supply Chain

Connect with IBM experts and your peers on the Supply Chain Collaboration Community and the Order Management Interest Group

Restrict/Filter the files based on the content types in Pre-Upload to SI

  1. Using mailbox and SFTP user exits we can perform a check on the file in pre-upload and can restrict the file uploads based on the file extensions.
  2. But Users can rename the file and send malicious (like .exe ) files to the system.
  3. It would be good if we can read the metadata of the file and perform the check in Pre-Upload rather than only file extension.
  4. This is a compliance issue for  Banking firms.
  • Avatar32.5fb70cce7410889e661286fd7f1897de Guest
  • Oct 3 2018
  • Needs More Information
How will this idea be used?

 Extension of the userexit capabilities to read the file metadata will be globally helpful for many organizations especially for banking organizations. This helps in security point of view for the banking industries to restrict/filter the file uploads at the time of pre-upload. 

What is your industry? Banking
What is the idea priority? Urgent
DeveloperWorks ID
Link to original RFE
  • Attach files
  • Admin
    Ryan Wood commented
    13 Jan 07:23pm

    Thank you for participating in the request for enhancement community. Your feedback is valued. We have analyzed this request and would like to ask for more information.

    With the following:

    Pre File Upload-

    Allows you to execute custom java code when FTP server has received command to put a file. This allows you to read the filename and you can use this to perform validation and many more. In case your code returns 'false', server will send a negative reply to client indicating file transfer failure. Also you can specify error message to be displayed at client end with 451 response code.

    Is this request to provide sample custom java code? Or an example/reference?