In Marketplace review · Updated October 8, 2026
Security
Architecture
- Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
- The setup is stored in Forge storage in your Atlassian cloud. Nothing about requests or customers is stored.
- No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.
- Read-only: the app has no write permissions in Jira.
What a customer sees, and only that
- The request key and portal come from Jira's page context, never from the browser.
- Before showing anything, the app asks Jira as the customer whether they may open the request, and checks that it belongs to the portal being viewed. For customers Jira can't be asked about, it checks reporter, participants and shared organizations.
- Fail closed: any doubt or error shows nothing.
- Only the items configured for that portal are read and returned. Comments, work logs, attachments, security levels, description and environment can't be configured.
- Linked issues the customer can't open never show their key, title or workflow status name.
- Values are sent as plain text; nothing customers see is rendered as HTML.
Who can change the setup
- Jira admins: every portal and the default. Checked on the server on every call.
- Service project admins: only their own portal, if a Jira admin allows it.
Permissions (scopes)
| Scope | Why |
|---|---|
| storage:app | Store the setup |
| read:jira-work | Read the chosen fields, status history, links and sub-tasks; check admin rights |
| read:jira-user | Show the assignee's display name when chosen |
| read:servicedesk-request | Check a customer may open a request; read SLAs, participants and status history |
| read:servicedesk:jira-service-management | List portals and match a project to its portal |
| read:requesttype:jira-service-management | Request type conditions |
| read:organization:jira-service-management | Customer organization conditions |
Reporting a vulnerability
Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.
Questions? Email support@bobob.app. Bobob Apps · bobob.app