atlassian / atlassian/github-for-jira
Updated permissions request: "Read and write access to Contents"
- Dominant language
- No language data
- Stars
- 655
- Forks
- 194
- PR merge metrics
- No merged PRs in 30d
Description
Dear Jira Team,
I got an updated permission request last night from the Jira app for Github:
> Read and write access to Contents
> We have updated the contents permissions from 'read-only' to 'read & write.' We have done this so you can create a branch from a Jira Issue.
In the latest version of the Readme (https://github.com/atlassian/github-for-jira/blob/37134b68e9a1181a6dfd7dd5e8cc5b526b807b0b/README.md, Augst 24th), only "Read-only for Contents" is listed.
I do not wish to enable Write access to content because the "Create Branch" feature is not something that is helpful enough to warrent granted another service write access to my repository. I understand that Atlassian is taking security seriously, as stated in other threads on the permission topic, however, the least privilege principle still compells me to be as restrictive as possible.
Please advise on how to best handle this new app permission request. From what I gather, it's not possible to simply deny some permissions, so right now, I'm just not approving the updated permission request and wait what happens next.
Thanks for your consideration and help,
Michael
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with README.md at the cited revision and compare its documented Contents permission with the permission request reported in the issue. Determine whether the mismatch is expected or requires a documentation or product change; done means the permission behavior and least-privilege guidance are clearly resolved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- authorization
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100