Uploaded image for project: 'Atlassian Product Integrations'
  1. Atlassian Product Integrations
  2. API-794

Allow more granular permissions for Jira Cloud for Slack

XMLWordPrintable

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • None
    • Jira Cloud for Slack
    • None
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Issue Summary

      Currently, the Slack integration with Jira Cloud does not provide sufficiently granular permission controls to restrict user actions and notifications in accordance with strict InfoSec requirements. Organizations need the ability to limit the integration to one-way notifications and prevent unlinked Slack users from accessing Jira data or interacting with the bot beyond basic notifications.

      Steps to Reproduce

      1. Integrate Jira Cloud with a Slack workspace using the official Atlassian Slack integration.
      1. Configure channel notifications and attempt to restrict permissions so that only authorized, linked users can receive notifications or interact with the Slack bot.

      Expected Results

      • Administrators should be able to configure the integration so that only Slack users who have linked their Atlassian accounts can receive notifications and interact with the Jira Slack bot.
      • It should be possible to restrict the integration to a one-way notification system, preventing any user (especially unlinked users) from performing Jira actions or accessing sensitive information via Slack.
      • More granular permission controls should be available to align with organizational InfoSec policies.

      Actual Results

      • Slack users who have not linked their Atlassian accounts can still receive channel notifications and see link unfurling. There is no way to restrict notifications or bot interactions solely to linked users. Permission controls are not granular enough to meet strict InfoSec requirements.

      The below security concern is observed:

      Unlinked Slack users are able to receive Jira issue notifications and view link previews in Slack channels, even when they have not authenticated with Atlassian. This may expose sensitive information and does not comply with certain InfoSec policies. 

      Workaround

      Currently there is no known workaround for this behavior. 

              Unassigned Unassigned
              6ddbd1c1e1be Dishon Victor
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: