I want to create a new defect against JIRA. How can I do that or what the the url for it. This is the defect
In https://confluence.atlassian.com/jirakb/security-headers-in-jira-939919914.html, it is written how to exclude the security header using com.atlassian.jira.clickjacking.protection.exclude. But com.atlassian.jira.clickjacking.protection.exclude does not support regular expression. Like if I update setenv.bat with
-Dcom.atlassian.jira.clickjacking.protection.exclude=/plugins/servlet/oslcservices/adminlogin,/plugins/servlet/oslcservices/oauth/approvekey,/plugins/servlet/oslcservices/userlogin,/plugins/servlet/oslcservices/oauth/authorize
itworks. But if I change it to
-Dcom.atlassian.jira.clickjacking.protection.exclude=/*/oslcservices/*
It does not work. So, this solution works for static url. But there are few urls which are dynamic because they will have project area id or issue id. Having support for regular expression or giving a way to support dynamic url is very much required.