You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Atlassian fixed FRGE-2205: remotes referenced in permissions.external.fetch.client only allowed the default base URL, so browser (Custom UI / client-side) requests to a remote's regional endpoints were blocked by the content security policy. Three concrete changes:
Client fetch permissions for a remote now cover the remote's regional base URLs, not just the default baseUrl.
New field remoteInstallationRegion on the result of getAppContext() (@forge/api), so an app can read which region its remote installation lives in.
App versioning: adding a client-fetch URL that already exists in fetch.backend is now a minor version change (it previously bumped major).
Parity implications for forge-sim
Shims (@forge/api): getAppContext() needs to return remoteInstallationRegion. Decide what the simulator reports (likely a configurable value defaulting to the remote's default region, or undefined when the remote has no operations/regional config).
Remotes / manifest: if forge-sim validates or enforces permissions.external.fetch.client against remote baseUrl (CSP emulation in forge-sim dev, or the remote fetch proxy), it must accept regional URLs declared on the remote, not only the default base URL. Blocking regional URLs is now a parity bug.
Limits / versioning behavior: forge-sim's deploy version-bump logic, if it models major/minor classification of manifest diffs, should treat "client URL already present in backend list" as minor.
GUID: CHANGE-3509
Published: Wed, 07 Oct 2026 02:57:44 GMT
Category: Announcement
Link: https://developer.atlassian.com/platform/forge/changelog/#CHANGE-3509
What's changing
Atlassian fixed FRGE-2205: remotes referenced in
permissions.external.fetch.clientonly allowed the default base URL, so browser (Custom UI / client-side) requests to a remote's regional endpoints were blocked by the content security policy. Three concrete changes:baseUrl.remoteInstallationRegionon the result ofgetAppContext()(@forge/api), so an app can read which region its remote installation lives in.fetch.backendis now a minor version change (it previously bumped major).Parity implications for forge-sim
Shims (
@forge/api):getAppContext()needs to returnremoteInstallationRegion. Decide what the simulator reports (likely a configurable value defaulting to the remote's default region, orundefinedwhen the remote has nooperations/regional config).Remotes / manifest: if forge-sim validates or enforces
permissions.external.fetch.clientagainst remotebaseUrl(CSP emulation inforge-sim dev, or the remote fetch proxy), it must accept regional URLs declared on the remote, not only the default base URL. Blocking regional URLs is now a parity bug.Limits / versioning behavior: forge-sim's
deployversion-bump logic, if it models major/minor classification of manifest diffs, should treat "client URL already present in backend list" as minor.forge-spec: update affected requirement rows (behavior change)