Why has the Text module been disabled from the JIRA OnDemand Gadgets Plugin ?

Jean-Denis Bernier June 28, 2013

It seems that suddently, the Text module has been disabled and now all our informative dashboard turned to ashes.. Is there a reason beside the potential security risk of having HTML code that could lead to XSS attack vulnerability ?

Thanks

2 answers

0 votes
Jean-Denis Bernier July 8, 2013

After filing a support ticket I've been told that the Text gadget has been disabled to prevent potential XXS attack from embedded HTML code in the gadget. No plan to reactivate it. :(

Pete Schwind Jr. October 14, 2013

This doesn't seem like an acceptable answer. I'm sure there's a way in which you could have a text gadget and not be susceptible to XXS atracks. The text gadget is a really great way to communicate to teams, especially when teams rely on dashboards as information radiators.

0 votes
Marlon Aguiar
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
July 3, 2013

Hi Jean-Denis,

I'm not sure if this specific module has been disabled on purpose, this might be a glitch affecting your instance. Would you mind opening a support ticket at support.atlassian.com so we can check why this has happened and possibly re-enable this module for you?

Regards,
Marlon

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events