Question about XSS protection for plugins

Daisuke Niwa December 18, 2012

Hi there,

I have a question about "Anti XSS module for plugins" within the security configuration screen of Confluence admin console.

One customer reported that when they enable this, the amount of connection between Confluence and DB increased dramatically.

Does it correspond to XSSSecurityHeader added to xwork?

Also, anyone happens to know how this Anti XSS module works?

Regards,

Daisuke Niwa

1 answer

1 accepted

1 vote
Answer accepted
VitalyA December 31, 2012

This is what you're looking for: https://developer.atlassian.com/display/CONFDEV/Enabling+XSS+Protection+in+Plugins

XSSSecurityHeader serves a different purpose and was introduced only recently.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events