Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,297,942
Community Members
 
Community Events
165
Community Groups

Text gadget in jira

Hi all,

I want to use Text gadget in jira to write some text and link websites on my dashboard but enabling text gadget makes jira instance vulnerable to XSS attacks. Is that okay to enable the text gadget? Can someone suggest me please.
Thank you

2 answers

2 accepted

4 votes
Answer accepted

 

Alternatively, you can create an issue within Jira and add your text/links to the Description field of an issue. Once you do this, create a filter based on the newly created issue 

ex:

issue = "ABC-1"

Next, go to your dashboard and add a Filter Results gadget and select your newly created filter based. For the section Columns to display, select only Description and save. 

You should now see your text/links. 

Regards,

Javier A. 

I tried this. A good alternative solution. Thank you so much

thanks Javier.   your solution although a hack, works.  much appreciated.

Thank you for the alternative solution

1 vote
Answer accepted

Samanth,

 

In regards to your question, that is really up to a personal preference.   The Text Gadget is disabled by default because it is a potential security risk, as it can contain arbitrary HTML which could potentially make your JIRA system vulnerable to XSS attacks as stated in our documentation Adding the Text Gadget.

That being said, the risk can really depends on your usage.  If you are running on a local network only and you trust your users to not abuse the gadget, then it should be okay to be used in your JIRA.

Again, this is something that you'll have to weigh the pros and cons about.   There are a few listings in our marketplace for Rich Text add-ons, that might be worth taking a look at to see if they are able to replace the functionality in the Text Gadget.

In JIRA Cloud we've removed the Text Gadget to avoid any potential security risks and suggest users look into the Rich Text Gadget on our Marketplace.

I hope this helps answer your question Samanth.

 

- Josh Loe

Thank you so much for your help

the Atlassian "Rich Text Gadget for Jira" doesn't appear work for Jira Cloud.    It installs ok, but isn't visible under the available gadgets.

What about the server version? Are there any secure alternatives to the Text Gadget?

@joshloe, is there another option to the Rich Text Gadget now that this gadget appears to no longer be found in the Marketplace?

Like # people like this

Suggest an answer

Log in or Sign up to answer
TAGS

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you