The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can I block Cloud OAuth 2.0 app REST API for Security?

Tom
December 27, 2023

We have registered a whitelist for accessing only the URLs permitted by the internal Proxy.

 

OK https://company1.atlassian.net

OK https://api.atlasian.com (And other necessary domain)

NG https://myself.atlassian.net  (User's personal website)

 

User cannot access myself.atlassian.net from company.

But if use a OAuth 2.0 app, can call api form api.atlassian.com/ex/jira bypass access to  myself.atlassian.net.

 

Question:

Can I block rest api from  OAuth 2.0 app in my proxy? I think two ways.

AND  will anyelse affect to jira/wiki's normally use?

 

  1. block "api.atlassian.com/ex/"
  2. block "api.atlassian.com" witch contain "Authorization: Bearer" in HTTP header

 

 

OAuth 2.0 document (3.2 Construct the request URL)

https://developer.atlassian.com/cloud/jira/platform/oauth-2-3lo-apps/

image (8).pngimage (9).png

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Deleted user
December 28, 2023

Hello @Tom 

I've never heard of anyone wanting to block access to the OAuth 2.0 mechanisms for 'security'.

Why not try it, see what what effect it has, then come back and provide a full report of the outcome? That way, if anyone else ever thinks of doing it in the future, they will know what to expect.

DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
FREE
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events