- From: Web Application Formats Working Group Issue Tracker <sysbot+tracker@w3.org>
- Date: Tue, 15 Jan 2008 14:22:41 +0000 (GMT)
- To: public-appformats@w3.org
ISSUE-21: What is the Security Model for the access-control spec? [Access Control] http://www.w3.org/2005/06/tracker/waf/issues/ Raised by: Arthur Barstow On product: Access Control The AC4CSR spec is missing a description of its Security Model. For example, what is the threat model for attacks such as CSRF, XSS, etc. This issue was raised by the WSC WG during its joint f2f meeting with the WAF WG on 5 November 2007: <http://www.w3.org/2007/11/05-waf-minutes.html#item09> It has also been a subject of discussion within e-mail exchanges on the public-appformats mail list: <http://lists.w3.org/Archives/Public/public-appformats/>
Received on Tuesday, 15 January 2008 14:22:51 UTC