In Marketplace review · Updated October 7, 2026
Security
Architecture
- Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
- Data is stored in Forge storage in your Atlassian cloud.
- No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.
Access control
- Every management action is checked on the server against Confluence permissions: site banners require Confluence admin; space banners require admin of that space. Showing or hiding a settings page is never treated as permission.
- Space admins can only see and change banners of their own space.
- When a space admin lists members of a targeted group, the app reads with that admin's own Confluence permissions, so it never reveals a list they couldn't see in Confluence.
- Viewers can only record a close or confirmation for a banner that is showing and is meant for them.
Data handling
- Banner messages are rendered as text with a small, safe formatting set (bold, links, line breaks). No HTML or scripts from banner content ever run. Links must be http(s) or mailto.
- Importing a Data Center banner removes scripts, event handlers, styles and unsafe links.
- CSV exports protect against spreadsheet formula injection.
- Errors shown to admins never include internal details; details go only to the app's Forge logs.
Permissions (scopes)
| Scope | Why |
|---|---|
| storage:app | Store banners and confirmations |
| read:confluence-user | Show names of people who confirmed |
| read:confluence-groups | Group targeting and "who hasn't confirmed" |
| read:confluence-space.summary, read:space:confluence | Space targeting and space admin checks |
| read:confluence-content.summary, read:page:confluence, read:blogpost:confluence, read:label:confluence | Page label targeting and page titles in insights |
Reporting a vulnerability
Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.
Questions? Email support@bobob.app. Bobob Apps · bobob.app