Hi,
my current Confluence 5.8.15 / TomCat 8 instance seems to add a "X-Frame-Options: SAMEORIGIN" header to all responses. How can I disable or modify this behavior? (please no security discussion )
Same issue over here! Since we upgraded to Confluence 5.8.16 we experience an issue that all iFrame integrations do not work anymore. Additionally, we had multiple issues with the new sameorigin policy since we use a Tivoli Access Manager in front of our Tomcat.
behavior seems to be related with the option:
antiClickJackingEnabled c.f. https://tomcat.apache.org/tomcat-8.0-doc/config/filter.html
antiClickJackingEnabled
c.f.
Because I didn't want to change the default configuration, I rewrote my plugin to use JSONP instead of been loaded within an iframe.
Jens, just saw on https://jira.atlassian.com/browse/CONF-29230 and from the source in SecurityHeadersInterceptor.java that -Dconfluence.clickjacking.protection.disable=true might help. Please try that, i haven't checked it yet
We had this setting enabled on Confluence 5.8.16 which worked fine. Now, on Confluence 5.8.18 it does not work anymore. I could not find any information on this on the release notes of Confluence, which is very bad
We are also experiencing this issue since upgrading Confluence to 5.8.18 and need to find a way for at least one space within our Confluence instance to be able to be viewed through an iframe. Have either of you had any more luck with this?
It looks like you're new here. Sign in or register to get started.