I am developing a JIRA add-on that creates a JIRA issue. I cannot use basic authentication (that is using the admin username and password) for the REST API calls because of functional requirements henceforth, I have to stick with JWT.
I am using the atlassian-jwt module for node.js to generate the JWT token:
var now = moment().utc();
var req = {
method: 'GET',
originalUrl: '/rest/api/2/application-properties/advanced-settings'
};
var token = {
"iss": 'issuer-val',
"iat": now.unix(), // the time the token is generated
"exp": now.add(3, 'minutes').unix(), // token expiry time (recommend 3 minutes after issuing)
"qsh": jwt.createQueryStringHash(req) // [Query String Hash](https://developer.atlassian.com/cloud/jira/platform/understanding-jwt/#a-name-qsh-a-creating-a-query-string-hash)
};
var secret = 'The shared secret that I receive while installing the add-on';
var token = jwt.encode(token, secret);
The token that I am receiving above I am using the same to call the REST API. However even a simple GET request like:
https://my-dev-enviroment.atlassian.net/rest/api/2/application-properties?jwt=the-jwt-token
returns Unauthorized 401
I have provided the required scopes in the atlassian-connect.json file as well.
"scopes": [
"read", "write"
]
I couldn't find any relevant source pertaining to my problem on the internet and have been searching for hours now.
Anyone with experience in developing add-ons for JIRA please guide me.