hi all,
we have a user requesting to enable the text dashboard and says it is useful for reports and dashboards. i read the documentation and i'm not following how this can be useful. since it says there are security risks involved , i would like yo make a decision based on pros and cons.
we have set the create shared objects permission for all logged in users and our JIRA is internal to our network
please provide input.
thanks !
Hello,
The Text gadget lets you add custom HTML to your dashboard which means you could write any script using html and javascript. For example you could add links to a page or draw a custom form in your dashboard, call any resource from your network(or internet if internet access is available). The possibilities are limitless.
There can be danger because you can add arbitrary HTML which could potentially make your JIRA system vulnerable to XSS attacks. If it is in your internal network, I would not be so worried about it.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.