Does confluence cloud allow changing x-frame-options header ?
Currently its set to SAMEORIGIN, and prevents any confluence page to be embedded in an iframe from a different domain.
No. You need to hack the code (or settings in Tomcat for this one, I think).
Changes like that are restricted functions, in order to keep the system supportable.
I think Confluence Server is not a problem as we get to control the environment. But my question is specifically about Confluence Cloud. I'm looking for a way to change the header to allow from few safe authorized urls, as mentioned in the specs - https://developer.mozilla.org/en-US/docs/Web/HTTP/X-Frame-Options
Cloud is what I answered for.
Do we have access to Tomcat settings in Confluence Cloud? I mean when I signup for confluence on atlassian.net do we get access to change anything on the server? From Confluence Admin settings I don't see an option to change anything for Tomcat / Java etc.
It looks like you're new here. Sign in or register to get started.