Recently a client was asking us to implement Content-Security-Policy and/or X-Frame-Options in our addon.
After some discussion we still don't have a clear idea on the matter. Does it make sense to implement CSP in Confluence Cloud apps?
Our guess is that our frames won't work out of context unless you have a valid signed jwt. So we should be safe there.
Does Atlassian have any suggestion or answer on this matter?
Regards,
Hugo
May also be worth posting the question here https://community.developer.atlassian.com/ :)
You should definitely configure the Content Security Policy (CSP) for your Apps in the Cloud.
CSP reduces the attack vector of all kinds of vulnerabilities, e.g.
Sometimes, just by answering these questions, you can find things that are out of place.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.