Visit site

Securely for Jira

Securely began with a concerning piece of news: the Okta hack (https://sec.okta.com/harfiles), which had significant repercussions for companies like 1Password and Cloudflare. This event highlighted a critical vulnerability in handling HAR files, which contain potentially sensitive customer data. A HAR file, or HTTP Archive format file, is a JSON-formatted log of a web browser's interactions with a site. When you visit a website, your browser makes a series of requests and receives responses: these are what a HAR file records, capturing the precise details of these exchanges. Developers and support teams (including Atlassians') often utilize HAR files for performance analysis, diagnosing errors, and tracking down network issues. When Okta was compromised, attackers were able to use customer submitted HAR files to then attack Okta’s customers. Shortly after the hack, Cloudflare released an open-source library for HAR file scrubbing, a proactive step in protecting sensitive data. This development caught my attention, but it was the confluence 😉 of this news and an Atlassian webinar, led by Neal Mansilla, that truly sparked my imagination. Neal was demonstrating the rapid development capabilities of Atlassian's Forge platform, and I found myself wondering: Could I leverage Forge to integrate Cloudflare's functionality into an app before the end of the one hour webinar? I fell short of my ambitious goal. However, within a week, not only had I developed a working version, but I also managed to release Securely on the Atlassian Marketplace. As someone who is less than stellar (read: bad) at coding, this was a significant achievement, made possible in no small part, through the assistance of ChatGPT, which handled most of the coding. Securely listens for Forge events which tell us when a new attachment is added to Jira, then we automatically scrub the file based on the app settings, attach the new file to Jira, and update references to it in issue comments. This ensures that if a user account or even your whole Jira Software or Jira Service Management site were to be compromised, an attacker couldn’t use HAR files to then attack your customers like what happened in Okta’s case. Design is not my forte either, but with the help of ChatGPT, DALL-E, and Vectorizer.ai, I created a logo for Securely. For the Atlassian Marketplace promotional images, I turned to Canva, which helped me put together something eye-catching yet straightforward by modifying existing templates. After the initial release, I quickly launched a configuration UI, allowing users to specify which attributes to scrub from their HAR files. Thanks to using Atlassian Design tokens from the start, this UI supported Dark Mode, enhancing user experience from the first day it went live. The initial version of Securely processed HAR files through a Cloudflare worker. This approach was quick to implement but had two main drawbacks: 1. Customer data had to leave Atlassian systems 2. The file transfer times between AWS and Cloudflare were significant and ate into my 55 second Forge function execution limit Recognizing these issues, I migrated the scrubbing process to Forge. This shift not only bolstered data privacy, security, and compliance but also slashed processing times from 40 seconds to just 1 second for HAR files near our current 99MB limit. This improvement is crucial as it paves the way for supporting larger HAR files in the future. But wait… There isn’t more yet.. But, I invite you to give Securely a try, explore its capabilities, and share your feedback. Every install, rating, and comment propels us toward a future where customer trust is absolute, and the privacy of their data is uncompromised. I have a slew of improvements I want to build for Securely and would love to hear from you.Securely for Jira screenshot