Environment properties:
Identity Manager 14.3
Cumulative patch 2
Wildfly 15
No Hotfixes
2 nodes of jboss
2 nodes of provisioning/connector server
1 node with Siteminder
1 node with Report Server
Release : 14.3
Component : JASPERSOFT REPORTS FOR IDENTITY MANAGER
customer logged
Firefox : The HTTP X-XSS-Protection
response header is a feature of Internet Explorer, Chrome and Safari that stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.
fiddle trace shows : X-XSS-Protection: 1; mode=block
Chrome : Access-Control-Allow-Origin lets you easily perform cross-domain Ajax requests in web applications.
1. use server FQDN to login IDM user Console .
Doing this it will avoid the Cross site scripting (CORS) policy blocking the css from browser and report was displayed as expected.
http://identmanage_FQDN.example.net:8080/iam/im/domain2/busobjservlet/flow.html?.xxxxxx