www-infrastructure-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Jakob Frank (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (INFRA-6994) JSONP support for the JIRA's REST API
Date Wed, 13 Nov 2013 13:03:23 GMT

    [ https://issues.apache.org/jira/browse/INFRA-6994?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13821288#comment-13821288
] 

Jakob Frank commented on INFRA-6994:
------------------------------------

Hi,

I was not aware of security issues with jsonp, as for CORS - we're often using an Apache HTTPD
proxy to access an application server.

Normally, we just add the following lines to the proxy config to allow the most common CORS
requests:
Header always set Access-Control-Allow-Origin "*"
Header always set Access-Control-Allow-Methods "POST, GET, OPTIONS"
Header always set Access-Control-Allow-Headers "Accept, Content-Type"

Not sure whether this fits with your security requirements - but if yes, it would be great
to have it enabled.
Thanks!

> JSONP support for the JIRA's REST API
> -------------------------------------
>
>                 Key: INFRA-6994
>                 URL: https://issues.apache.org/jira/browse/INFRA-6994
>             Project: Infrastructure
>          Issue Type: Wish
>          Components: JIRA
>            Reporter: Jakob Frank
>            Assignee: Tony Stevenson
>
> In Marmotta, we'd like to list the available versions from JIRA in the website.
> We had this feature enabled and working (INFRA-5938) but in JIRA 6, jsonp support is
removed by default.
> Would it be possible to re-enable jsonp, or alternatively configure CORS Headers?
> Thanks!
> https://developer.atlassian.com/display/JIRADEV/Preparing+for+JIRA+6.0#PreparingforJIRA6.0-JSON-Pnolongersupported



--
This message was sent by Atlassian JIRA
(v6.1#6144)

Mime
View raw message