In Marketplace review · Updated October 8, 2026
Security
Architecture
- Built on Atlassian Forge. Code runs on Atlassian's infrastructure; there are no servers of ours.
- Data is stored in Forge storage in your Atlassian cloud.
- No egress: the app declares no external domains and makes no calls outside Atlassian. It is eligible for Atlassian's "Runs on Atlassian" program.
Access control
- Every management action is checked on the server: Confluence admin for every space, or admin of that space (which a Confluence admin can turn off).
- A rule can only be created under a page that the person can see, in a space they manage.
- Space admins can only see and change rules of their own spaces.
Data handling
- The app moves pages within the tree; it never reads, changes or stores page content.
- Before each run it saves the previous order, and after each run it reads the tree back to confirm the result.
Permissions (scopes)
| Scope | Why |
|---|---|
| storage:app | Store rules, run history and undo snapshots |
| read:confluence-user | Check that the person is a Confluence admin |
| read:confluence-space.summary, read:space:confluence | Read spaces and check space admin rights |
| read:confluence-content.summary, read:page:confluence, read:hierarchical-content:confluence | Read page titles, dates and the order of child pages |
| search:confluence | Find pages by title when choosing a parent |
| write:confluence-content | Move pages to their new position |
Reporting a vulnerability
Email support@bobob.app with "Security" in the subject. We acknowledge within 72 hours and fix critical issues as a priority.
Questions? Email support@bobob.app. Bobob Apps · bobob.app