Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can I block Cloud OAuth 2.0 app REST API for Security?

Tom December 27, 2023

We have registered a whitelist for accessing only the URLs permitted by the internal Proxy.

 

OK https://company1.atlassian.net

OK https://api.atlasian.com (And other necessary domain)

NG https://myself.atlassian.net  (User's personal website)

 

User cannot access myself.atlassian.net from company.

But if use a OAuth 2.0 app, can call api form api.atlassian.com/ex/jira bypass access to  myself.atlassian.net.

 

Question:

Can I block rest api from  OAuth 2.0 app in my proxy? I think two ways.

AND  will anyelse affect to jira/wiki's normally use?

 

  1. block "api.atlassian.com/ex/"
  2. block "api.atlassian.com" witch contain "Authorization: Bearer" in HTTP header

 

 

OAuth 2.0 document (3.2 Construct the request URL)

https://developer.atlassian.com/cloud/jira/platform/oauth-2-3lo-apps/

image (8).pngimage (9).png

1 answer

0 votes
Sunny Ape
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 28, 2023

Hello @Tom 

I've never heard of anyone wanting to block access to the OAuth 2.0 mechanisms for 'security'.

Why not try it, see what what effect it has, then come back and provide a full report of the outcome? That way, if anyone else ever thinks of doing it in the future, they will know what to expect.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
FREE
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events