Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can we require users of an Issue Collector form to be authenticated?

dave_drexler
Contributor
April 24, 2023

Hi folks - we'd like to use an Issue Collector to allow Salesforce users in our company to file a Jira issue while they're filing a Salesforce customer encounter. The Salesforce users may or may not also have accounts in Jira. The Salesforce users will be logged into Salesforce, but may or may not be also logged into Jira.

Our IT group is concerned that the Issue Collector code could in some way prove to be a vulnerability; that bad actors could somehow use the collector code to get into Jira. And they've asked whether we can force a user of an Issue Collector dialog to authenticate themselves against our Active Directory so that if the Issue Collector were somehow launched outside of Salesforce it wouldn't work.

Any advice? Has anyone else faced this concern?

2 answers

1 accepted

0 votes
Answer accepted
Brant Schroeder
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 15, 2023

@dave_drexler There is no way to make it so that the issue collector requires a user to log in to use it.  If you place it on a website that requires authentication then it will be hard for a bad actor to find the code.  The only thing it would allow them to do is to submit an issue through the API to Jira that is all the code is doing.  

dave_drexler
Contributor
August 15, 2023

thank you, @Brant Schroeder .

0 votes
Alex Medved _ConfiForms_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 15, 2023

I guess you need to open the project in Jira for anonymous submission.

Otherwise you need to login to Jira, before using the issue collector as @Brant Schroeder mentioned

Alex

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events