public-webappsec@w3.org from January 2012 by subject

[webappsec WG] Security Considerations for CORS with credentials

[webappsec-testsuite] Test VM - how to share it?

[webappsec] Including URI fragment in CSP reports (ACTION-43)

[webappsec] No call tomorrow, Jan 31.

[webappsec] straw man anti-clickjacking proposal

Agenda for WebAppSec WG call: Jan 17, 2012, 22:00 UTC

CSP and HTML manipulation by Internet Access Providers

First policy policy (Action 34)

JSON patch format

WebAppSec WG call agenda, Jan 3, 2012 22:00-23:00 UTC

webappsec-ISSUE-10: Processing model for object element and frame-src directive

webappsec-ISSUE-11: Violation report privacy issues

webappsec-ISSUE-12: Should 'self' be required to be replaced by explict host in reports?

webappsec-ISSUE-9: Should the user agent fire the error event when an img-src load fails?

Last message date: Tuesday, 31 January 2012 17:34:53 UTC