Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If forge lint misses a Jira call wrapped in your own helper, don’t assume the helper is the cause. Atlassian documents a specific limitation: lint does not support Jira Cloud REST API v2 paths; it supports only /rest/api/3 paths. Its documentation does not establish whether lint follows every custom helper or dynamically constructed URL. Trace the request to its final method and path, look up that operation’s OAuth scopes, and check your manifest yourself.

What Forge lint does—and what it does not establish

Atlassian says forge lint can help identify missing scopes, and forge lint --fix can add detected scopes to manifest.yml. Treat the fix as an aid, not a complete audit: it adds scopes it detects but does not remove redundant ones. Review the manifest and remove unnecessary scopes manually. Atlassian’s scope workflow explains the lint and fix process.

The documented Jira path limitation is precise. Atlassian’s Forge REST API reference, last updated November 8, 2024, says Jira Cloud REST API v2 is not supported by forge lint; only /rest/api/3 paths are supported. That is a documented reason lint may not recognize a request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Atlassian’s documentation does not say whether lint follows arbitrary custom JavaScript helpers, wrapper layers, or computed URL strings. So a helper-wrapped call may need manual checking, but the helper itself is not a proven cause. If you need to establish how a particular code shape behaves, reproduce it with a minimal Forge project, recording the Forge CLI version, request code, lint output, and expected scope.

Trace the helper to the actual Jira operation

Start with the request that actually goes over the network, not the helper’s name. Follow each call through wrapper functions and resolve templates, concatenated strings, and variables until you know the final HTTP method and Jira path.

  1. Open the helper implementation and trace its callers to the request it sends.
  2. Write down the final HTTP method and complete Jira REST path, resolving any dynamic parts.
  3. Check the path version. If it is under /rest/api/2, lint’s inability to support that path is documented. If it is under /rest/api/3, continue checking the exact operation and scope rather than assuming the helper is the issue.
  4. Find that operation in the Jira REST API documentation and read its OAuth scopes required field. Do not infer a scope from a helper’s name or a similar-looking endpoint.

Atlassian’s Atlassian app REST APIs reference links to REST API documentation and describes the supported authenticated APIs. Use the documentation for the specific operation you call.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose and declare the required scope

Add the minimum scopes required by the operations your app uses under permissions.scopes in manifest.yml. The operation’s documentation is the source for the required scope; don’t add broader access simply because lint did not identify a helper-wrapped request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where a classic scope is available, Atlassian recommends using it. Keep the declared scope set lean, remove redundant entries manually, and aim to keep the total below 50 scopes, as recommended on Atlassian’s Jira product scopes page. The Forge permissions reference explains manifest declarations and operation-level scope lookup.

Apply the change and check access separately

  1. Update permissions.scopes in manifest.yml with the operation’s required scope.
  2. Run forge lint again. You can try forge lint --fix for calls lint recognizes, but inspect the manifest diff and verify helper-wrapped or otherwise unsupported calls yourself.
  3. Run forge deploy, then forge install --upgrade. Atlassian says scope changes do not take effect until the app is upgraded; deploying alone is not the final step.
  4. If the request still fails, check the acting user’s Jira permissions separately. An app OAuth scope does not grant that user permission to see or modify a project or its data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.