-
Type:
Suggestion
-
Resolution: Unresolved
-
None
-
Component/s: Administration - Secrets Management
-
None
-
1
-
3
Problem Definition
At the moment, the OUath : write permissions for OAuth gives write access to include any actions permitted to the user, who may be admin and have total access.
Integraitons using a global admin account may need to be restricted from certain actions like deleting projects, etc..
Suggested Solution
Provide more granular OAuth permissions for 'write' scope, e.g. separate permissions for deleting projects, etc.
This way, integrations can be restricted to certain type of actions or certian projects, providing better security.
- relates to
-
JRACLOUD-85195 OAuth Integrations: Provide more granular scope options for setting Integration access constraints
- Gathering Interest