Action required: Atlassian Connect vulnerability allows bypass of app qsh verification via context JWTs

Thanks for the explanations.

Some of the HTML links describes in the descriptor, such as dialogs, cannot be validated (JWT/QSH) because JWT token is not sent with the request: AP.Dialog doesn't provide JWT token on URL call

Is it planned to also include these for JWT/QSH validation and so, include JWT/QSH in the request ?

Thanks for your reply.