Clocker Get Clocker

Security

Security overview – Clocker for Jira

How Clocker protects your data, for security reviews and the Atlassian Marketplace security questionnaire.

Architecture

Permissions (OAuth scopes)

Scope Used for
read:jira-work Searching issues, reading issues, worklogs and permissions
write:jira-work Creating, updating and deleting worklogs
read:jira-user Reading the current user's profile (time zone) and global time tracking settings
storage:app Preferences, timers and site settings in Forge storage
report:personal-data Atlassian's weekly personal data report: erasing the data of closed accounts

The app requests no admin or configuration-management scopes.

Authorisation

Input handling

Content Security Policy

The Custom UI runs in Forge's sandboxed iframe with the default CSP. The only relaxation is permissions.content.styles: unsafe-inline, which the Atlassian Design System's runtime styles require. No external scripts, fonts or images are loaded. Avatars are rendered as initials so no image hosts need to be allowed.

Dependencies

Reporting a vulnerability

Open a request in the support portal, or email support@niedzwiecki.dev with "Security" in the subject, with details and steps to reproduce. Please don't include customer data. We acknowledge reports within two business days and fix them within the timelines of Atlassian's Marketplace security bug fix policy.