Guest access no longer supported after switching to Forge
Since migrating our SharePoint Connector app from Atlassian Connect to Forge, customers with external users (guest accounts) have been experiencing issues accessing embedded SharePoint content. The cause is the fixed path structure of the Forge manifest for OAuth2 authentication.
Possible effects:
External users receive an error message.
The access permission configuration is displayed, but does not lead to success.
The expected message "Approval required" does not appear.
Technical background:
Forge uses a fixed path /organizations/oauth2/ for OAuth2 flows.
This path cannot be configured on a tenant-specific basis.
Guest users are typically connected to their own tenant and therefore cannot see content from the app operator's tenant.
Current measures:
Although the Forge Platform improves security, guest access is currently unavailable. We submitted an improvement ticket to Atlassian about parameterizing the OAuth2 path and hope they resolve this soon. You can add your vote here: https://jira.atlassian.com/browse/CONFCLOUD-80208
The more visibility the item has, the higher the chances its priority will increase.