I have a issue in JSM where some of the images and javascript library in use come from the CDN cloudfront but the that domain is not in CSP permissions file of the app so they get blocked and we get broken images and functionality.
This is covered in manual for people that self-host, but, we are hosted by Atlassian and don't seem to have access to the variable that would allow us to change that.
Has anyone come across this?
This is the CSP they are using for us where you can see it does not include the needed *.cloudfront.com
frame-ancestors 'self' *.atlassian.net *.jira.com *.atl-paas.net *.atlassian.com trello.com bitbucket.org *.jiraalign.com;
report-uri https://web-security-reports.services.atlassian.com/csp-report/jira-frontend-bifrost;
report-to csp-default-endpoint
(I have raised a ticket with Atlassian with all the details and screenshots but the person that picked it up doesn't understand nor is escalating it so I have "hit a brick wall")
https://confluence.atlassian.com/conf84/use-a-cdn-with-atlassian-data-center-applications-1255449373.html
