public-webappsec@w3.org from May 2015 by subject

[Bug 28620] New: vbvcb

[credential management] Cross-origin credentials (was: Identity Credentials API Extension)

[credential management] Identity Credentials API Extension

[credential-management] Risk in same origin and SSL/TLS requirements

[CSP2] Preventing page navigation to untrusted sources

[CSP3] Question on the use case of the CSP request header

[mixed-content] How to move "localStorage" or "IndexedDB" from HTTP to HTTPS?

[REFERRER] 301 Redirections with cross origin and same origin nodes?

[REFERRER] origin-when-crossorigin OR origin-when-cross-origin

[REFERRER] policy inheritance via javascript: URI and new document

[REFERRER] Referrer Policy Test Suite - The first batch is in!

[SRI] Comments on Subresource Integrity spec

[SRI] integrity + login looks broken

[SRI] Requiring CORS for SRI

[SRI] review note 1

[SRI] review note 2

[SRI] Some new tests

[webappsec] Monday Teleconference HOMEWORK

[webappsec] proposed Teleconference Agenda 4-May-2015 (Subresource Integrity)

[webappsec] Teleconference Monday June 1 CANCELLED

Abusing HTTP status codes to deanonymize web users

Call for Exclusions (Update): Content Security Policy Pinning

CfC: Subresource Integrity (SRI) to Last Call?

Comments on Subresource integrity

F2F Meeting?

Harmonizing same-origin and cross-origin credentials

Logjam and Resetting Handshake Timers in Browsers

Microsoft is considering Chrome's Native Messaging

Monday May 18 teleconference topics

Permissions API vs local APIs

Proposal: Two changes to iframe@sandbox

SRI for preemptive cache validation

The jQuery CDN has enabled CORS (Re: [SRI] Requiring CORS for SRI)

Last message date: Saturday, 30 May 2015 04:14:22 UTC