Security – Portal Insight for Jira Service Management
Architecture
- Built on Atlassian Forge and eligible for Runs on Atlassian: all compute and storage run on Atlassian's infrastructure, there are no external hosts, no remotes, no web triggers and no data egress.
- The only stored data is the per service desk configuration, in Forge hosted storage of your site, following its data residency.
What a portal user can and cannot see
- Viewer check first. For every request page, the app first reads the request with the viewer's own permissions through the Jira Service Management API. If the viewer cannot see the request, the panel shows nothing and the app reads no further data.
- Allow-list per service desk. Only fields an administrator selected are read and shown. Comments, attachments, worklogs, watchers and votes can never be selected. Unconfigured service desks show nothing.
- Linked requests. The recommended mode re-checks every linked issue with the viewer's permissions and lists only requests they can open. The two modes that list all linked issues are an explicit administrator choice, labelled as such in the settings. In those modes linked issues are read with the app's access, so issue security levels and project permissions of the linked issues do not hide them; the key and status (and in one mode the summary) become visible to customers.
- Fields that reveal other issues (parent, sub-tasks) cannot be selected.
- Server-side rendering. The browser receives display-ready text only: no raw issue data, account IDs or e-mail addresses.
Who can change the configuration
- The settings page and its backend functions check, on the server, that the calling user holds the Jira Administer Jira global permission. Others get no data and cannot save.
- Portal users can reach only one read-only backend function, which enforces the checks above.
Permissions requested from Atlassian
| Scope | Why |
|---|---|
read:servicedesk-request |
Check as the viewer that they can see the request and linked requests; list service desks on the settings page |
read:jira-work |
Read the approved fields and SLA fields; list fields on the settings page; check the Administer Jira permission |
storage:app |
Store the per service desk configuration |
Development practices
- Automated tests cover the viewer check, the allow-list, link modes, SLA rendering, access control on the settings page and translations.
- A security review runs before every release (see release notes).
- The app writes no logs containing request data or personal data.
Reporting a vulnerability
E-mail support@687.monster with the subject "Security". We acknowledge within 2 business days and follow Atlassian's Marketplace security requirements for fix timelines.