CSP and HTML manipulation by Internet Access Providers
[webappsec wg] Draft minutes from 12/20/2011 for approval on next call
[webappsec WG] Security Considerations for CORS with credentials
[Bug 15312] New: lowercasing requirement for Access-Control-Request-Headers harmful
Draft meetings from Dec 06 call
RE: W3C WebAppSec WG F2F meeting
CSP versus Content-Type on scripts and stylesheets
RE: W3C WebAppSec WG Meeting (regrets)
Meeting reminder
WebAppSec WG call agenda, Dec 20, 2011, 22:00-23:00 UTC
CfC: CORS to advance to Last Call
W3C WebAppSec WG Meeting
no-external-navigation
Proposal: CSP "allow-modification" directive
ISSUE-4: Policy combination
- RE: ISSUE-4: Policy combination
- Re: ISSUE-4: Policy combination