When creating a connect app, you are free to define the structure of the descriptor per the app's needs.
One of the options is also a key `jiraProjectPages` that allows to append an app link into the project sidebar.
However, you as a plugin developer might not want to display the app link on each and every one project, so you can impose conditions when it should display.
The conditions are defined here: https://developer.atlassian.com/cloud/jira/platform/connect-conditions
One of the options is to have the sidebar's app link displayed by the value of a project property.
For example:
"jiraProjectPages": [
{
"key": "project",
"name": {
"value": "App name"
},
"url": "project-url",
"conditions": [
{
"condition": "user_is_logged_in"
},
{
"condition": "entity_property_equal_to",
"params": {
"entity": "project",
"propertyKey": "app.key",
"objectName": "isEnabled",
"value": "true"
}
}
],
}
],
This is a good solution. But the problem here is privacy.
Actually ANY LOGGED USER can read and update project properties.

However, if this seems to be a security problem, there is no other way how to show/hide the project sidebar link.
So even if there is a privacy risk, should such solution be used to store an information whether the app link is displayed/hidden?