The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CSP

Magnus Tamm
December 16, 2019

Hey.

Can I modify CSP to use noonce to restrict using inline scripts? Or what are the possibilities to solve my problem?

Best wishes,

Magnus

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
December 16, 2019

You will need to explain what you mean by "CSP" and what it has to do with Atlassian software.

Magnus Tamm
December 16, 2019

Oh yes. Sorry for my poor explanation. 

I'm talking about security headers. Right now csp is set as: Content-Security-Policy: frame-ancestors 'self'

But it allows to run inline scripts in jira. So you can run HTML <script> elements or on-event handlers to run XSS type attacks. 

So the resulution is to calculate every script hash or use nonce. But can I change these settings in jira? Can i set csp to nonce and if yes then how and where?

TAGS
AUG Leaders

Atlassian Community Events