본문으로 건너뛰기
bobob

In Marketplace review · Updated October 8, 2026

Security

Architecture

  • Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
  • Data is stored in Forge storage in your Atlassian cloud.
  • No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.

Access control

  • Every management action is checked on the server: Confluence admin for every space, or admin of that space (which a Confluence admin can turn off).
  • A rule can only be created under a page that the person can see, in a space they manage.
  • Space admins can only see and change rules of their own spaces.

Data handling

  • The app moves pages within the tree; it never reads, changes or stores page content.
  • Before each run it saves the previous order, and after each run it reads the tree back to confirm the result.

Permissions (scopes)

ScopeWhy
storage:appStore rules, run history and undo snapshots
read:confluence-userCheck that the person is a Confluence admin
read:confluence-space.summary, read:space:confluenceRead spaces and check space admin rights
read:confluence-content.summary, read:page:confluence, read:hierarchical-content:confluenceRead page titles, dates and the order of child pages
search:confluenceFind pages by title when choosing a parent
write:confluence-contentMove pages to their new position

Reporting a vulnerability

Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.

Questions? Email support@bobob.app. Bobob Apps · bobob.app