Broader Jira app permissions than needed

From Jira, I see the app has these permissions:

Locu can perform the following actions:

  • View user information in Jira that the user has access to, including usernames, email addresses, and avatars.

  • Fetch, register, refresh, and delete dynamically declared Jira webhooks.

  • Read Jira project and issue data, search for issues, and objects associated with issues like attachments and worklogs.

  • Create and edit issues in Jira, post comments as the user, create worklogs, and delete issues.

I suppose Jira webhooks are needed for real-time sync from Jira to Locu, that’s okay.

But I don’t get why can it:

  • create issues - i don’t see this option inside Locu

  • edit issues - i cannot edit the Jira task from Locu

  • post comments - i cannot post comments

  • create worklogs - i don’t see the option

  • delete issues - i cannot delete

Every one of these options I want to be able to disable them IF they are implemented. And if they’re not implemented, the app shouldn’t have those permissions at all. I was really hesitant allowing this app to be connected to Jira. Please this is really important for me and possibly for your other users.

Please authenticate to join the conversation.

Upvoters
Status

Completed

Board

💡 Feature Request

Date

About 2 months ago

Author

Ivan Harašta

Subscribe to post

Get notified by email when there are changes.