No way to refresh trusted apps current application keys

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Fixed
    • Component/s: None

      NOTE: This suggestion is for JIRA Cloud. Using JIRA Server? See the corresponding suggestion.

      The trusted apps current application keys are stored in a lazy reference in DefaultCurrentApplicationFactory. They are not reset by a cache cleared event, and there is no way to refresh the keys without restarting JIRA. This causes a problem in JIRA Studio where we have often needed to refresh keys. Use cases as follows:

      • Security breach requires resetting of all secrets
      • A customers import contains their old keys, which poses security risks to both Atlassian and the customer
      • Studio changes the way keys are managed to a shared key between all apps

      Since the keys are stored in ApplicationProperties, it is simple for Studio to set/change them, however, those changes won't be picked up until JIRA has restarted. This request is specifically for a mechanism to clear the cache without restarting JIRA.

            Assignee:
            bain
            Reporter:
            James Roper [Atlassian]
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: