Uploaded image for project: 'Confluence Cloud'
  1. Confluence Cloud
  2. CONFCLOUD-82596

Enable Allowed Domain List for Attachment Access in Forge Apps

XMLWordPrintable

    • 1
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Summary of the Issue

      With the deprecation of the Connect framework and the migration of vendors to Forge, stricter security measures have been introduced. Forge apps, by default, restrict access to external URLs, only allowing communication with the current site URL. This presents a challenge when a Confluence or Jira Cloud site changes its domain (e.g., from abc.atlassian.net to xyz.atlassian.net), but attachments or resources still reference the old domain. As a result, Forge-based apps are unable to render these attachments, leading to broken user experiences and data accessibility issues.

      Suggestion for Implementation

      Introduce a configurable "Allowed Domain List" or "Domain Exception List" in Forge app permissions. This list would enable admins or app vendors to specify additional trusted domains (such as previous site URLs) from which attachments and resources can be accessed. The implementation should:

      • Allow explicit listing of old site domains in the Forge app manifest.
      • Ensure that only domains previously owned by the organization or verified by Atlassian can be added, to maintain security.
      • Optionally, provide an admin UI for managing allowed domains post-migration.

      Workaround

      Currently, the only officially supported workaround is to reupload the attachments in such cases.

              Unassigned Unassigned
              e671084fd175 Kshitiz Awasthi
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: