To follow up https://community.atlassian.com/t5/Statuspage-questions/X-Frame-Options-and-CSP-HTTP-Headers/qaq-p/2335218. If our public status page is tested against clickjacking it results vulnerable to this kind of attack, due to the lack of X-Frame-Options and CSP HTTP headers. Is there a way to set X-Frame-Options and CSP in HTTP response headers?
Do we have this feature added?
Hey Chhaya! I just checked the feature request, STATUS-96, and it hasn't been released yet. The engineering team is still gathering interest, and I've marked your question here as interested in seeing the feature implemented.
Feel free to reach out via support.atlassian.com if you want more information or have other questions.
Thanks,
Jessie
Hi @Jessie Turpin any update on this?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Jareth Rossking The feature request is still under consideration by the engineering team.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.