It seems that the default status page script uses an iframe without sandbox attributes, so it can cause some security audit issues.
Can this be added to the script by default without developers having to extract it out?
Thank you.
Thank you for reaching out to the Atlassian Community. My name is Aditya, here to help!
I see you want to improve the security of the default StatusPage embed by including sandbox attributes in the generated iframe, addressing security audit issues automatically.
We do have a feature request that our Product and Engineering teams are actively considering adding this option—I have added this ticket to that request to help with its visibility. StatusPage Feature Requests are internal only, but if you ever want to ask for an update, please quote STATUS-96.
Let me know if you have any additional questions. I’ll be happy to help!
Thank you,
Aditya
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.