I'm interested in securing paths in our Jira & Confluence installations so that there are no anonymously available URLs that will load.
This means all unauthenticated requests will redirect to the login page.
I don't know if any special considerations will need to be given for TrustedApps.
I poked around Jira and seems there's an actions.xml file where I can specify role-required in several areas. There also seems to be a way to do it via Seraph, and use seraph-paths.xml to define it.