[webappsec] adding data to CSP reports with DOM API
[webappsec] Agenda for Telecon 17 Jul 2012
[webappsec] Call tomorrow CANCELLED - join WebSec @ IETF 84, 9:00-10:20 PST
[webappsec] Telecon agenda for WebAppSec WG call of July 3
[webappsec] TPAC registration and joint meetings
[websec] Coordinating Frame-Options and CSP UI Safety directives
Call for Exclusions: Content Security Policy
Coordinating Frame-Options and CSP UI Safety directives
CORS proxy - was: CORS security hole?
CORS security hole?
CSP 1.1: `script-nonce` and script interface edits.
CSP 1.1: Behavior when presented with an invalid plugin-types directive?
CSP 1.1: More granular source list definitions.
Regarding Action 67
script and data uri
Secure dynamic JS compilation under CSP
some further Comments on Content Security Policy 1.0 Editor's Draft
TPAC 2012 Registration
webappsec-ISSUE-15 (SRCDOC, BLOB, ETC): How to handle srcdoc, blob:, di: and ways of directly creating content
Why the restriction on unauthenticated GET in CORS?
- Henry Story (Saturday, 21 July)
- Eric Rescorla (Saturday, 21 July)
- Henry Story (Saturday, 21 July)
- Jonas Sicking (Saturday, 21 July)
- Ian Hickson (Friday, 20 July)
- Henry Story (Friday, 20 July)
- Tab Atkins Jr. (Friday, 20 July)
- Henry Story (Friday, 20 July)
- Adam Barth (Friday, 20 July)
- Cameron Jones (Friday, 20 July)
- Adam Barth (Friday, 20 July)
- Cameron Jones (Friday, 20 July)
- Adam Barth (Friday, 20 July)
- Cameron Jones (Thursday, 19 July)
- Cameron Jones (Thursday, 19 July)
- Anne van Kesteren (Thursday, 19 July)
- Cameron Jones (Thursday, 19 July)
- Eric Rescorla (Thursday, 19 July)
- Anne van Kesteren (Thursday, 19 July)
- Cameron Jones (Thursday, 19 July)
- Henry Story (Thursday, 19 July)
- Cameron Jones (Thursday, 19 July)
- Henry Story (Wednesday, 18 July)
- Ian Hickson (Wednesday, 18 July)
- Henry Story (Wednesday, 18 July)
Last message date: Tuesday, 31 July 2012 21:44:59 UTC