Hey,
Starting a thread to hear what other Jira Admins/Users are doing to tackle this...
Keen to hear how you protect the base64 encoded authentication inside your A4J rules?
Occurred to me that maybe an attribute insight an Insight Object inside a locked down schema could potentially work? I just worry about project admin's accessing the rule and using the auth inside the web request.
Aware it could be set as a global rule to prevent project admin's accessing but still not really great from a security perspective