Saturday, 29 September 2012
Thursday, 27 September 2012
Tuesday, 25 September 2012
- Re: CORS test status
- Re: CSP 1.1: Paths in source list definitions.
- Regrets 9/25
- Re: CORS test status
- Re: CORS test status
- Re: CORS test status
- Re: CORS test status
- Re: CORS test status
- CORS test status
- RE: test
- RE: test
- RE: Agenda for September 25 Call
- CfC: FPWD of UI Safety Directives for CSP
- test
- Re: [CSP] Extensions and user script? (Some feedback)
- Re: [CSP] Extensions and user script? (Some feedback)
- Re: CSP 1.1: Paths in source list definitions.
- Regrets for today's call.
- Re: CSP 1.1: Paths in source list definitions.
- Agenda for September 25 Call
Sunday, 23 September 2012
- Re: CSP connect-src and browser plugins
- Re: CSP connect-src and browser plugins
- CSP connect-src and browser plugins
- Re: CSP 1.1: Paths in source list definitions.
Thursday, 20 September 2012
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- RE: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
Wednesday, 19 September 2012
- Re: CSP Sandbox directive and meta tag - CSP 1.1
- Re: unsafe-inline for style-src
- RE: CSP Sandbox directive and meta tag - CSP 1.1
- RE: CSP Sandbox directive and meta tag - CSP 1.1
- Re: CSP Sandbox directive and meta tag - CSP 1.1
- Re: unsafe-inline for style-src
- RE: CSP Sandbox directive and meta tag - CSP 1.1
Tuesday, 18 September 2012
- Re: unsafe-inline for style-src
- CSP Sandbox directive and meta tag - CSP 1.1
- unsafe-inline for style-src
Monday, 17 September 2012
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- Web Crypto WG - Web Crypto API going to FPWD
- Re: CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
Sunday, 16 September 2012
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
Friday, 14 September 2012
- [webappsec] "certificates differ" text in CORS
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- Re: CSP 1.0 browser compliance testing
- Re: CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
Thursday, 13 September 2012
- RE: CSP 1.0 browser compliance testing
- Re: CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
- CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
- Re: ISSUE-6 comments addressed
- Re: ISSUE-6 comments addressed
- Re: some further Comments on Content Security Policy 1.0 Editor's Draft
- ISSUE-6 comments addressed
Wednesday, 12 September 2012
- RE: New clickjacking research published
- Re: UI Safety - input protection obstruction check challenges
- UI Safety - input protection obstruction check challenges
Tuesday, 11 September 2012
- Re: some further Comments on Content Security Policy 1.0 Editor's Draft
- [webappsec] Agenda for today's WebAppSec WG call
- RE: New clickjacking research published
Monday, 10 September 2012
Tuesday, 11 September 2012
- RE: New clickjacking research published
- webappsec-ISSUE-19 (Interaction of CSP and IRIs): How are non-ASCII characters handled in CSP
- webappsec-ISSUE-18 (CSP as risk assessment score): Use CSP to report app risk and compatibility with user specified restrictions
- webappsec-ISSUE-17 (Extension compat): CSP should take into account extensions which modify content
- webappsec-ISSUE-16 (CSP informs client, cannot restrict it): Editorial: CSP cannot dictate client behavior, only inform it
- RE: [webappsec] Major update to UI Safety
- Re: New clickjacking research published
- RE: New clickjacking research published
- RE: [webappsec] Major update to UI Safety
- Re: New clickjacking research published
- [webappsec] Major update to UI Safety
Monday, 10 September 2012
- Re: script-tag with html template-content
- script-tag with html template-content
- Feedback on the Content Security Policy 1.0
- Re: CSP 1.0 browser compliance testing
Friday, 7 September 2012
- CSP 1.0 browser compliance testing
- Re: Interaction of CSP and IRIs
- Re: Interaction of CSP and IRIs
- Re: Interaction of CSP and IRIs
- Re: [webappsec] Call for Consensus: Content Security Policy 1.0 to Candidate Recommendation
Thursday, 6 September 2012
- Re: Interaction of CSP and IRIs
- Interaction of CSP and IRIs
- Re: Call for Consensus: Content Security Policy 1.0 to Candidate Recommendation