Does confluence cloud allow changing x-frame-options header ?
Currently its set to SAMEORIGIN, and prevents any confluence page to be embedded in an iframe from a different domain.
No. You need to hack the code (or settings in Tomcat for this one, I think).
Changes like that are restricted functions, in order to keep the system supportable.
I think Confluence Server is not a problem as we get to control the environment. But my question is specifically about Confluence Cloud. I'm looking for a way to change the header to allow from few safe authorized urls, as mentioned in the specs - https://developer.mozilla.org/en-US/docs/Web/HTTP/X-Frame-Options
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Cloud is what I answered for.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Do we have access to Tomcat settings in Confluence Cloud? I mean when I signup for confluence on atlassian.net do we get access to change anything on the server? From Confluence Admin settings I don't see an option to change anything for Tomcat / Java etc.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
As I already said, changes like that are restricted functions.
You can not change this stuff.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Sure Nic, then we are same page, because anything that as a customer I can't change (even can't hack) is essentially considered not possible in my opinion.
I see you have a enhancement ticket opened here - https://jira.atlassian.com/browse/CONF-40640 in which you mention confluence.clickjacking.protection.disable as a way, but unless customer has a way to set this property, essentially there is no way, isn't? I'll +1 on your ticket, as this looks like a very important enhancement request to enable reusing confluence pages by embedding them elsewhere.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Ah, it's not my issue, I'm not an Atlassian, but yes, vote on that to encourage them to enable something.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.