jira/v2/app/iframe endpoint provide Set-Cookie parameter in Response Header without security parameter. For Chrome browser display warning: "This Set-Cookie header didn't specify a “SameSite" attribute and was defaulted to "SameSite=Lax," and was blocked because it came from a cross-site response which was not the response to a top-level navigation. The Set-Cookie had to have been set with “SameSite=None" to enable cross-site usage." So plugin_session cookie is not stored in browser and I'm not able to load images - get request for img has Request header without plugin_session parameter