Does the feature to set X-Frame-Options in HTTP response headers is added?

Chhaya Patil (C)
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 14, 2024

To follow up https://community.atlassian.com/t5/Statuspage-questions/X-Frame-Options-and-CSP-HTTP-Headers/qaq-p/2335218. If our public status page is tested against clickjacking it results vulnerable to this kind of attack, due to the lack of X-Frame-Options and CSP HTTP headers. Is there a way to set X-Frame-Options and CSP in HTTP response headers? 

 

Do we have this feature added?

1 answer

0 votes
Jessie Turpin
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 15, 2024

Hey Chhaya! I just checked the feature request, STATUS-96, and it hasn't been released yet. The engineering team is still gathering interest, and I've marked your question here as interested in seeing the feature implemented. 

Feel free to reach out via support.atlassian.com if you want more information or have other questions. 

Thanks,

Jessie

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events