To follow up https://community.atlassian.com/t5/Statuspage-questions/X-Frame-Options-and-CSP-HTTP-Headers/qaq-p/2335218. If our public status page is tested against clickjacking it results vulnerable to this kind of attack, due to the lack of X-Frame-Options and CSP HTTP headers. Is there a way to set X-Frame-Options and CSP in HTTP response headers?
Do we have this feature added?
Hey Chhaya! I just checked the feature request, STATUS-96, and it hasn't been released yet. The engineering team is still gathering interest, and I've marked your question here as interested in seeing the feature implemented.
Feel free to reach out via support.atlassian.com if you want more information or have other questions.
Thanks,
Jessie
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.