Skip to main content
Skip table of contents

Scopes & Permissions

External domains (for images):

  • *.atlassian.com : We cannot upload images directly to the survey in Cloud because the images get part of the JSON which is then too big for the Storage API of Forge. Instead, it is possible to upload images to a Confluence page as an attachment and link this attachment. Because attachments are stored on api.media.atlassian.com, we whitelist *.atlassian.com for images.

  • *.atlassian.net : Used to retrieve a user's Confluence profile picture.

  • *.wp.com : We need this to retrieve user avatars for users that do not have a profile picture, e.g., https://i2.wp.com/avatar-management--avatars.us-west-2.prod.public.atl-paas.net/initials/MB-0.png?ssl=1. We are mirroring this from Atlassian, who do the same call when retrieving such user avatars.

  • fonts.gstatic.com : SurveyJS introduces some fonts for the survey creator. We retrieve the fonts so the editor is displayed correctly.

  • surveyjs.io: SurveyJS shows some demonstration pictures when inserting an image picker question. We retrieve exactly these four images to give a good user experience.

    • https://surveyjs.io/Content/Images/examples/image-picker/lion.jpg

    • https://surveyjs.io/Content/Images/examples/image-picker/giraffe.jpg

    • https://surveyjs.io/Content/Images/examples/image-picker/panda.jpg

    • https://surveyjs.io/Content/Images/examples/image-picker/camel.jpg

Scopes:

These are the scopes defined for our app. Please note that their representation in the “Allow Access” dialog can differ.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.