Restricted Confluence Space Access (Preview) — does it cover page restrictions, or only space permissions?

Confluence DC to Cloud. We strip page restrictions before the migration and put them back after.

The preview note says an app can access data from “restricted spaces that are part of the migration”, including spaces “restricted to a specific set of users or groups”. The word page does not appear anywhere on that docs page. CHANGE-3287 says spaces too.

RFC-122 started elsewhere. The scoping proposed there was per page, a macro on a page meaning access to that page. In January it became unfettered access to the restricted spaces.

And MIG-837, which is about page restrictions and the 403 an app gets on them, is closed as Fixed on the back of it. Elliot from the app migration team called the preview “restricted confluence page data” there.

Which is in scope in the migration window? A page in an open space, own view restriction, app user not on it. Readable? Writable?

Have not found anyone who has tested it since July.

Thanks for checking. Yes, migration mode covers restrictions on individual pages. In your example, if the page is part of the migration, a page-level view restriction that excludes the app user should not prevent the migrating app from reading it during the active app migration. This applies to updates as well.

This is temporary access for the migration; it does not remove or change the page’s restrictions. Once app migration ends, normal access rules apply again.
If you’re still seeing a 403 for that scenario during an active migration, please share the API endpoint and a request trace through support so we can investigate.

Thanks,
David

Hi @DavidYu, thanks, that settles it. Page-level view restrictions are covered for the migrating app during the active migration, reads and updates, and nothing changes on the page afterwards.