HolySN

VS Code

Editing a ServiceNow script field in VS Code, with the editor never talking to the instance and your session never leaving the browser.

HolySN Sync is a small VS Code extension. With it installed, a script field on any record opens as a file in VS Code, and saving the file puts the text back into the field.

Setting it up

Install HolySN Sync from the VS Code Marketplace, or search for it in VS Code's Extensions view. Once it is installed, HolySN appears in the status bar.

Editing a field

  1. Open a record with a script field.
  2. Click the ⌁ icon beside the field's label.
  3. The first time, the page shows a four-digit code and VS Code asks: Allow a browser to edit ServiceNow scripts in VS Code? Say yes only if VS Code shows the same code.
  4. The field opens as a file in a .holysn folder inside your workspace, and the Explorer shows it. With no folder open, VS Code adds a HolySN sync folder to the window instead. Save the file, and the text goes back into the field.

Saving in VS Code does not save the record. It sets the field, and submitting the form stays yours, the same rule the in-page field editor holds to.

The icon appears on every field that holds code: scripts, HTML, XML, JSON, CSS, conditions, and a few rarer types such as GraphQL schemas and translations.

/vscode opens the bridge page in the settings, and /vscode off disconnects both ends.

In the settings

The VS Code bridge section of the settings page shows whether the editor is reachable and approved, and lists the fields currently open in the editor. Release on one, or Release all, stops this browser accepting edits for it. Nothing on the instance changes.

The bridge listens on 127.0.0.1:39917 by default, and the port can be changed there. It stays below 49152 on purpose: above that is the range the operating system hands out to whichever program asks first.

What crosses, and what does not

The editor never talks to ServiceNow. It edits text and hands it back. The browser does the write, on the session already open in that tab.

Your session token never leaves the browser. The protocol has no field for a credential, and both ends refuse any message that carries one.

Only an approved browser gets in. An unknown caller reaches one thing, the request that asks you in VS Code, and gets nothing until you say yes. VS Code cannot tell for sure which program is asking, so the code is what you check: the browser picks it and shows it before it asks. If the question appears when you did not click anything, or the codes differ, something else on your machine is trying to connect: say no.

Synced files stay in their own folder. They go in .holysn inside the workspace, which ignores itself in git. Old ones are removed after seven days, and only files the bridge wrote are ever removed.

An edit can only touch the field it came from. What comes back from the editor is checked against what this tab sent, table, record and field, and dropped otherwise.

A ServiceNow page cannot reach the editor. The requests go through the extension's own worker, which builds the local address itself from a fixed list of four paths. A page can neither call the bridge directly nor use it to probe anything else running on your machine.

VS Code | HolySN