I have a user who wants me to add custom javascript to the "Custom HTML" section at the end of the Body in Confluence. The javascript hides the create button for a specific space. I've never liked adding custom scripting to the Confluence body or the header.
What security risks should I be aware of before I allow this change?
Do other Confluence admins allow custom javascript in the header or body of their spaces?
To clarify, I'm not referring to adding this as a macro. They want to use the System-level feature.
Thank you.
I allow it with caveats. I wouldn't give them all the rights to add it, but would add it for them IF I understand the code and they are a trusted source.
You could have them run it through a Vulnerability Scanning tool, several available online, and if Javascript is heavily used in your environment, you most likely already have a standard one.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.