Skip to content
View in the app

A better way to browse. Learn more.

JimiWikman.se

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Sinch: Securing Atlassian Data Center

Senior Atlassian Platform Owner Internal Project

Work description

Project Heimdall was a massive project where I went through a full security audit for the Atlassian Data Center products Confluence, Jira Software and Jira Service Management. During the audit I mapped out a number of activities such as securing the API's, revise the situation with how groups were being used as that was out of control, document integrations and ensuring that access was configured properly.

The first activity was to kick out everyone from system administration that was not a member of my team. After that I revised all access setting to ensure that the global permissions were set up properly and that the roles were properly defined and used within the permission schemas. I removed several roles and removed almost a hundred permission schemas to align access right to one common setup so that roles became the appropriate way to assign users to a project.

I removed groups from permissions and workflows and removed hundreds of groups that were unused or used the wrong way.

I removed a very poorly designed setup for legal compliancy and redesigned it using Assets and AD groups to ensure legal compliance was enforced without any possibility to override in the Atlassian platform. I also worked with legal and security to ensure that the setup was aligned throughout the organization in sales situation and contract signing processes.

I added Compass and forced all integrations to be listed there by securing the API's and turning off access to anyone that did not have a documented integration. The API's were only accessible through a special SAINT (System Account for INTegration) account that we controlled.

We also reviewed and corrected thousands of configurations in the products and the apps and made sure they were not in risk of a legal or security incident.

Tags

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.