Klob Apps

Security

SpecLens is built so that the safest option is the default one.

Architecture

Permissions and why

PermissionReason
read:attachment:confluenceList the attachments of the current page so the editor can pick the specification.
readonly:content.attachment:confluenceDownload the selected specification to render it.
Content: inline stylesRequired by the Swagger UI, Redoc and AsyncAPI viewers.
Content: runtime script evaluationRequired by the AsyncAPI parser, which compiles JSON schemas at runtime. The viewer runs in Forge's isolated frame without network access to other sites.

Reporting a vulnerability

Write to support@klobapps.com with "Security" in the subject. We acknowledge within 48 hours and fix vulnerabilities within the timeframes of the Atlassian Marketplace security requirements.