atlassian / atlassian/github-for-jira

Updated permissions request: "Read and write access to Contents"

Open
#1,728 39 comments 29 reactions 0 assignees View on GitHub
permissions question stay tuned
Dominant language
No language data
Stars
655
Forks
194
PR merge metrics
No merged PRs in 30d

Description

Dear Jira Team,

I got an updated permission request last night from the Jira app for Github:
> Read and write access to Contents
> We have updated the contents permissions from 'read-only' to 'read & write.' We have done this so you can create a branch from a Jira Issue.

In the latest version of the Readme (https://github.com/atlassian/github-for-jira/blob/37134b68e9a1181a6dfd7dd5e8cc5b526b807b0b/README.md, Augst 24th), only "Read-only for Contents" is listed.

I do not wish to enable Write access to content because the "Create Branch" feature is not something that is helpful enough to warrent granted another service write access to my repository. I understand that Atlassian is taking security seriously, as stated in other threads on the permission topic, however, the least privilege principle still compells me to be as restrictive as possible.

Please advise on how to best handle this new app permission request. From what I gather, it's not possible to simply deny some permissions, so right now, I'm just not approving the updated permission request and wait what happens next.

Thanks for your consideration and help,
Michael

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with README.md at the cited revision and compare its documented Contents permission with the permission request reported in the issue. Determine whether the mismatch is expected or requires a documentation or product change; done means the permission behavior and least-privilege guidance are clearly resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
authorization
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.