New clickjacking threats page
CSP HTTP header description
[webappsec] Call for tomorrow, 3/27, CANCELLED
[webappsec] CSP META tag support - keep or remove?
- Re: [webappsec] CSP META tag support - keep or remove?
- Re: [webappsec] CSP META tag support - keep or remove?
[webappsec] Refining CSP header definitions and advice to intermediaries
CSP - 'unsafe-inline' for 'style-src' directive, actually unsafe?
- Re: CSP - 'unsafe-inline' for 'style-src' directive, actually unsafe?
[Bug 16436] New: Resource processing: shouldn't need to split Origin string on SPACE anymore
[Bug 16434] New: Clarify that "global unique identifier" is an alias for "null" (for all CORS-purposes)
[webappsec] TPAC 2012 - Lyon, France, Oct 29-Nov2
[webappsec] Registration for F2F
webappsec-ISSUE-14 (META tag for CSP): Investigate whether to keep the META tag for CSP
FW: W3C WebAppSec WG Meeting
[webappsec] Updated agenda for 3/13 call
[webappsec] Agenda for WebAppSec call, today **21:00** UTC
XSS through content-sniffing: good case for CSP sandbox directive
[CORS] Review of CORS and WebAppSec prior to LCWD
Re: [webappsec] straw man anti-clickjacking proposal
[webappsec] Straw poll: policy-uri in CSP
- Re: [webappsec] Straw poll: policy-uri in CSP
- Re: [webappsec] Straw poll: policy-uri in CSP
- Re: [webappsec] Straw poll: policy-uri in CSP