main

Bulk transitions and raw API

Immutable bulk transition plans

Never pipe a JQL result directly into live mutations. Resolve it into a saved plan:

jrc issue bulk transition plan \
  --jql 'sprint in openSprints() AND status != Done' \
  --to Done --max 50 \
  --out /tmp/jayrat-transition-plan.json --output json

--max defaults to 50. Choose it deliberately for JQL plans, then verify the saved item count covers the user’s intended scope before application.

Inspect the saved keys and transition IDs, then validate application without writing:

jrc issue bulk transition apply /tmp/jayrat-transition-plan.json \
  --dry-run --output json

If the user’s request clearly authorises the complete saved set, apply that same file with --confirm. Do not rerun the JQL. Stop on the first error unless the user explicitly asks for --continue-on-error. Report every applied, failed, and not_run result.

Plans may also use --keys or --keys-file. Do not overwrite an existing plan without --force.

Raw API escape hatch

Use jrc api only when no typed command covers the request. Inspect the method, relative endpoint, and JSON body explicitly. Prefer --data-file.

  • Permit relative REST paths.
  • Permit an absolute URL only when its scheme, host, and port match the configured Jira origin.
  • Reject cross-origin URLs, embedded credentials, and redirects.
  • Treat POST, PUT, PATCH, and DELETE as mutations and dry-run them first.
  • Treat DELETE as destructive and require an unambiguous user request.