본문으로 건너뛰기
bobob

In Marketplace review · Updated October 8, 2026

Security

Architecture

  • Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
  • The setup is stored in Forge storage in your Atlassian cloud. Nothing about requests or customers is stored.
  • No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.
  • Read-only: the app has no write permissions in Jira.

What a customer sees, and only that

  • The request key and portal come from Jira's page context, never from the browser.
  • Before showing anything, the app asks Jira as the customer whether they may open the request, and checks that it belongs to the portal being viewed. For customers Jira can't be asked about, it checks reporter, participants and shared organizations.
  • Fail closed: any doubt or error shows nothing.
  • Only the items configured for that portal are read and returned. Comments, work logs, attachments, security levels, description and environment can't be configured.
  • Linked issues the customer can't open never show their key, title or workflow status name.
  • Values are sent as plain text; nothing customers see is rendered as HTML.

Who can change the setup

  • Jira admins: every portal and the default. Checked on the server on every call.
  • Service project admins: only their own portal, if a Jira admin allows it.

Permissions (scopes)

ScopeWhy
storage:appStore the setup
read:jira-workRead the chosen fields, status history, links and sub-tasks; check admin rights
read:jira-userShow the assignee's display name when chosen
read:servicedesk-requestCheck a customer may open a request; read SLAs, participants and status history
read:servicedesk:jira-service-managementList portals and match a project to its portal
read:requesttype:jira-service-managementRequest type conditions
read:organization:jira-service-managementCustomer organization conditions

Reporting a vulnerability

Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.

Questions? Email support@bobob.app. Bobob Apps · bobob.app