Just a heads up: On March 24, 2025, starting at 4:30pm CDT / 19:30 UTC, the site will be undergoing scheduled maintenance for a few hours. During this time, the site might be unavailable for a short while. Thanks for your patience.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Text gadget in jira

Sam
Contributor
April 18, 2018
Hi all,

I want to use Text gadget in jira to write some text and link websites on my dashboard but enabling text gadget makes jira instance vulnerable to XSS attacks. Is that okay to enable the text gadget? Can someone suggest me please.
Thank you

2 answers

2 accepted

14 votes
Answer accepted
Javi
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 19, 2018

 

Alternatively, you can create an issue within Jira and add your text/links to the Description field of an issue. Once you do this, create a filter based on the newly created issue 

ex:

issue = "ABC-1"

Next, go to your dashboard and add a Filter Results gadget and select your newly created filter based. For the section Columns to display, select only Description and save. 

You should now see your text/links. 

Regards,

Javier A. 

Sam
Contributor
May 1, 2018

I tried this. A good alternative solution. Thank you so much

Jira Automation October 15, 2018

thanks Javier.   your solution although a hack, works.  much appreciated.

Shantala Ramesh
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
May 4, 2022

Thank you for the alternative solution

6 votes
Answer accepted
joshloe
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 18, 2018

Samanth,

 

In regards to your question, that is really up to a personal preference.   The Text Gadget is disabled by default because it is a potential security risk, as it can contain arbitrary HTML which could potentially make your JIRA system vulnerable to XSS attacks as stated in our documentation Adding the Text Gadget.

That being said, the risk can really depends on your usage.  If you are running on a local network only and you trust your users to not abuse the gadget, then it should be okay to be used in your JIRA.

Again, this is something that you'll have to weigh the pros and cons about.   There are a few listings in our marketplace for Rich Text add-ons, that might be worth taking a look at to see if they are able to replace the functionality in the Text Gadget.

In JIRA Cloud we've removed the Text Gadget to avoid any potential security risks and suggest users look into the Rich Text Gadget on our Marketplace.

I hope this helps answer your question Samanth.

 

- Josh Loe

Sam
Contributor
May 1, 2018

Thank you so much for your help

Jira Automation October 15, 2018

the Atlassian "Rich Text Gadget for Jira" doesn't appear work for Jira Cloud.    It installs ok, but isn't visible under the available gadgets.

Andrea Roßkamp [Communardo] January 4, 2019

What about the server version? Are there any secure alternatives to the Text Gadget?

Jennifer Meacham January 27, 2019

@joshloe, is there another option to the Rich Text Gadget now that this gadget appears to no longer be found in the Marketplace?

Like # people like this
Dave Liao
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
December 30, 2024

As of December 2024, the Rich Text Gadget (from Atlassian Labs) is available on the Atlassian Marketplace - I just installed it in a Jira Cloud instance, with no issues.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events