Recently a client was asking us to implement Content-Security-Policy and/or X-Frame-Options in our addon.
After some discussion we still don't have a clear idea on the matter. Does it make sense to implement CSP in Confluence Cloud apps?
Our guess is that our frames won't work out of context unless you have a valid signed jwt. So we should be safe there.
Does Atlassian have any suggestion or answer on this matter?
Regards,
Hugo