Charter strawman for Web App Security WG (CSP, CORS+UMP)

FYI, we've published a charter strawman for a Web Application Security WG.

The mission of the Web Application Security Working Group, part of the Rich Web Client Activity, would be to develop security and policy mechanisms to improve the security of Web Applications, and enable secure cross-site communication.

The intended group would start work on a Content Security Policy specification intended to enable web designers or server administrators to adjust the HTML5 security policy, and specify how content interacts on their web sites.  It would also take up the CORS and UMP specifications currently under development in the Web Applications Working Group and advance them along the Recommendation Track as joint deliverables with that group.

We would expect this work to occur in close coordination with the IETF, and expect discussion about details of that coordination to occur at the HASMAT BOF at the upcoming IETF meeting.

The draft text is here:
	http://www.w3.org/2010/07/appsecwg-charter

Comments are more than welcome.

Regards,
--
Thomas Roessler, W3C  <tlr@w3.org>  (@roessler)

Received on Wednesday, 21 July 2010 14:59:51 UTC