Recent searches


No recent searches

Sid2's Avatar

Sid2

Joined Mar 04, 2024

·

Last activity Nov 04, 2024

Following

0

Followers

0

Total activity

7

Votes

2

Subscriptions

2

ACTIVITY OVERVIEW

Latest activity by Sid2

Sid2 commented,

Community comment Developer - Zendesk Apps Framework (ZAF)

Tipene Hughes  Is there any update on this? We are also facing this same issue during the development of our app

View comment · Posted Nov 04, 2024 · Sid2

0

Followers

0

Votes

0

Comments


Sid2 commented,

Community comment Developer - Zendesk Apps Framework (ZAF)

Hey Tipene,

My use case would be to securely store a user's access and refresh token in Zendesk. This app will be an extension of our software that allows it to integrate with Zendesk and the access and refresh token will be needed in Zendesk to access our software. 

I'm aware that there is an OAuth option in Zendesk Support Apps but that does put more effort on the user to generate the token. We are trying to create a token from Zendesk with just a single click. We also have our user-based handling, so different users of Zendesk can be other users in our software which ultimately requires us to store multiple access and refresh tokens based on the users. This eliminates app metadata settings as an option as it only has a single copy for all users. Currently, our only storage is to create a custom user field but that exposes a single user's token to other users of the same Zendesk instance.

Do we have any other options here to securely store this sensitive data? Or is there any way to hide the custom user fields just like we hide the fields in the ticket?

Thanks,
Sid

View comment · Posted Jul 17, 2024 · Sid2

0

Followers

1

Vote

0

Comments


Sid2 created a post,

Post Developer - Zendesk Apps Framework (ZAF)

As the title suggested, I am looking for user-based storage for support apps in Zendesk.

I have already looked into adding it to the manifest or custom user fields. The Major problem I am facing is the exposure of sensitive data.

Manifest/User Fields can be accessed by any user for any user. So storing something secure like an auth token for the admin in the admin's user field becomes a security risk as it can be retrieved by an agent using the correct API. 

Is there any storage for support apps that can be suitable for my use case?

Posted Mar 04, 2024 · Sid2

1

Follower

4

Votes

2

Comments