Hello community,
I would like to ask for assistance regarding a security of a connect app.
Firstly, a little big of context:
- our app link is displayed in Jira Software in the project sidebar
- a user can control, whether the link is displayed or hidden
This is accomplished by a module condition of `entity_property_equal_to` that toggles `enabled=true/false`.
The entity property is basically a "project property" that can be easily set/retrieved as so:
- `PUT /rest/api/2/project/{projectIdOrKey}/properties/{propertyKey}`
- `GET /rest/api/2/project/{projectIdOrKey}/properties/{propertyKey}`
Our app makes the http requests via AP.request() wrapper.
The problem occurs, when it comes to permissions.
The bug bounty team found out, that a user who lacks an administrative permission in Jira can easily open up the browser console and make a http request via AP.request() to update project properties (and basically enable/disable our plugin for any project).
Basically, here is probably no way how to secure updating the toggling properties from our app, because the wrapper `AP.request()` is available via the browser console and when having access to the browser console, the user can basically do whatever they like.
Is there any way or any advice you would give how to secure this?