Security – Migration Doctor for Jira Cloud
Architecture
- Built on Atlassian Forge and eligible for Runs on Atlassian: all compute and storage run on Atlassian's infrastructure, with no external hosts, no remotes and no data egress.
- Data is stored in Forge SQL inside your site and follows its data residency.
- The snapshot script runs on your own machine, only reads from Jira Data Center, takes its token from an environment variable and never writes it to the output.
Access control
- The admin page and every backend function check, on the server, that the calling user holds the Jira Administer Jira global permission. Others get no data.
- Cloud configuration is read with the permissions of the administrator who runs the checks.
- Uploaded snapshots are validated in the browser and again on the server, chunk by chunk.
Changes to your site
- Repairs need an explicit approval after a preview. Jira validates the new JQL before approval.
- Repairs run as the approving administrator and only create filters. The app never deletes or overwrites objects and never changes workflows.
- Each repair is recorded in a change log with the values before and after.
Permissions requested from Atlassian
| Scope | Why |
|---|---|
read:jira-work |
Read filters, dashboards, permission schemes, fields and projects; validate JQL |
write:jira-work |
Create a missing or corrected filter and hand it to its owner, only after approval |
read:jira-user |
Match Data Center users to Cloud accounts; check that groups exist |
manage:jira-configuration |
Read workflows with their transition rules. Jira offers no read-only classic scope for this; the app never changes configuration |
report:personal-data |
Weekly personal data report to Atlassian |
Development practices
- Automated tests cover snapshot validation, every check with positive, negative and edge cases, JQL rewriting, collection, the comparison, repairs, and privacy handling.
- A security review runs before every release.
- Logs contain counts only, never configuration or personal data.
Reporting a vulnerability
E-mail support@687.monster with the subject "Security". We acknowledge within 2 business days and follow Atlassian's Marketplace security requirements for fix timelines.