Hi,
Our Security sca
ns showed that the Atlassian DC Applications we have hosted (Jira, Confluence.. ) are lacking Security related Headers especially "Clear-Site-Data".
We have tried setting the headers on haproxy side, however it resulted in user's sessions getting timed out with each page navigation request.
This is what we have tried:
http-response set-header Clear-Site-Data: "cache", "cookies", "storage", "executionContexts", "*"
1) Is the Clear-Site-Data header required at a Global level for all page 'responses', OR should it be set only when the user tries to log out of Jira/ closes the tab ??
- If it's the former, will it clear the stored session of logged in user ?
- If it's the latter, how can we target the logout request alone ?
2) Do you have any docs/ tickets which talks about the syntax required for 'Clear-Site-Data' header to be set for Atlassian applications ?? ( I found this ticket : [https://jira.atlassian.com/browse/JRASERVER-71365\](https://jira.atlassian.com/browse/JRASERVER-71365))
Thanks,
Majo