feat(security-review): confluence-doc OAuth 2.0 client-credentials (service account) #40

Merged
amoussa1229 merged 1 commit from feat/confluence-doc-oauth into main 2026-06-22 23:45:42 +00:00

1 commit

Author SHA1 Message Date
a92d6f6480 feat(security-review): confluence-doc supports OAuth 2.0 client-credentials (service account)
Atlassian org service accounts have no classic API token — they authenticate via
OAuth 2.0 client-credentials (2LO). Add a dual-mode auth seam to confluence-doc:
- OAuth (preferred when CONFLUENCE_OAUTH_CLIENT_ID/_SECRET set): POST
  auth.atlassian.com/oauth/token (client_id+client_secret+grant_type=client_credentials)
  → 60-min Bearer; calls go to api.atlassian.com/ex/confluence/<cloudId>/wiki/api/v2/...
  cloudId auto-resolves from the site's public /_edge/tenant_info (no input needed).
- Basic (email+API token) retained as a fallback.
conf_api_init() picks the mode once; conf_get() does the authenticated GET. Any
failure (no cloudId / token request fails) → RUN_API=0, live checks SKIPPED, NO
false alarm (matches the existing no-data discipline). Secret passed in the request
body (--data-urlencode), never logged. Still read + recommend-only (D7); canary
unaffected (offline) — 3/3. shellcheck clean (accepted SC1091).
2026-06-22 19:44:35 -04:00