Hi,
To easily manage repositories from Jenkins (with multi-branch) I have to give access to a Bitbucket account to be able to list all repositories and so on.
For now the only solution is to use a pair of "username+password". To make things secure I use an app password with only "read roles" so nothing stupid can be done. Until here, it works well.
But my main concern is I'm using my personal Bitbucket account to manage multiple "teams/workspaces" into Bitbucket. So when creating an app password to enter it in my company Jenkins... if a Jenkins admin tries to change the "owner" of the pipeline it will see listed all my personal repositories for example (this is possible by using my personal username instead of the team username).
In this case an other Jenkins admin (who I can trust... but there are limits!) is able to see all my personal stuff. And if smart, could create a fake pipeline just to list the content of all the files inside.
After looking around, it seems there is no way to scope the app password to the team... if I'm right, what the heck is doing Atlassian to not provide this kind of secure feature? Nobody wants to have a bitbucket account per team...
Thank you,
Related post: https://community.atlassian.com/t5/Bitbucket-questions/How-do-I-generate-an-App-password-for-a-team-so-that-I-can-copy/qaq-p/689922?tempId=eyJvaWRjX2NvbnNlbnRfbGFuZ3VhZ2VfdmVyc2lvbiI6IjIuMCIsIm9pZGNfY29uc2VudF9ncmFudGVkX2F0IjoxNjQ3MzUxMzExMjc2fQ%3D%3D