Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-65796

Knowledge Base in JIRA Service Desk does not show the Content when "Header always append X-Frame-Options SAMEORIGIN" is added on the VirtualHost file

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Medium
    • None
    • 7.3.0, 7.4.2
    • Application Links

    Description

      Summary

      When viewing a Knowledge base article, it shows an empty content.

      Environment

      1. Both applications must use a different domain in order to reproduce the issue. As an example:
        • JIRA - "anna.cardino.com"
        • Confluence - "monique.cardino.com"

      Steps to Reproduce

      1. Configure proxy to JIRA and Confluence following Integrating JIRA with Apache
      2. Add this parameter to the VirtualHost file of JIRA and Confluence
        Header always append X-Frame-Options SAMEORIGIN
        
      3. Ensure that JIRA and Confluence are using different domain nama else, the issue won't be reproducible.
      4. Create an application link with OAuth Impersonation configured on Outgoing and Incoming
      5. Create a Service Desk project and link it to one of the Confluence spaces.
      6. Go to the Service Desk project and raise a request
      7. On the What do you need help with? field, type the title of the pages on the linked Space.
      8. Search works fine as per the search.png
      9. Click on the title link

      Expected behaviour

      The page will display it's content

      Actual Behaviour

      It shows an empty content empty.png

      Notes

      Removing the header parameter in the VirtualHost file fixes the problem. However, it is not advisable due to security risk. It was also mentioned as a workaround in JRASERVER-25143

      Workaround

      No known workaround.

      Attachments

        1. empty.png
          empty.png
          54 kB
        2. search.png
          search.png
          63 kB

        Activity

          People

            Unassigned Unassigned
            acardino Anna Cardino (Inactive)
            Votes:
            6 Vote for this issue
            Watchers:
            8 Start watching this issue

            Dates

              Created:
              Updated: