Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Does the feature to set X-Frame-Options in HTTP response headers is added?

Chhaya Patil (C)
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 14, 2024

To follow up https://community.atlassian.com/t5/Statuspage-questions/X-Frame-Options-and-CSP-HTTP-Headers/qaq-p/2335218. If our public status page is tested against clickjacking it results vulnerable to this kind of attack, due to the lack of X-Frame-Options and CSP HTTP headers. Is there a way to set X-Frame-Options and CSP in HTTP response headers? 

 

Do we have this feature added?

1 answer

0 votes
Jessie Turpin
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 15, 2024

Hey Chhaya! I just checked the feature request, STATUS-96, and it hasn't been released yet. The engineering team is still gathering interest, and I've marked your question here as interested in seeing the feature implemented. 

Feel free to reach out via support.atlassian.com if you want more information or have other questions. 

Thanks,

Jessie

Jareth Rossking
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 15, 2025

Hi @Jessie Turpin any update on this?

Jessie Turpin
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 16, 2025

Hi @Jareth Rossking The feature request is still under consideration by the engineering team. 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events