Regrets 9/25
CORS test status
CfC: FPWD of UI Safety Directives for CSP
test
Re: [CSP] Extensions and user script? (Some feedback)
Regrets for today's call.
Agenda for September 25 Call
CSP connect-src and browser plugins
CSP Sandbox directive and meta tag - CSP 1.1
unsafe-inline for style-src
- Re: unsafe-inline for style-src
- Re: unsafe-inline for style-src
[webappsec] "certificates differ" text in CORS
RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
- RE: CSP 1.0: relaxing mandated enforcing and monitoring to avoid
CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
- Re: CSP 1.0: relaxing mandated enforcing and monitoring to avoid probing and to avoid content being written to depend on CSP.
ISSUE-6 comments addressed
UI Safety - input protection obstruction check challenges
Re: some further Comments on Content Security Policy 1.0 Editor's Draft
[webappsec] Agenda for today's WebAppSec WG call
webappsec-ISSUE-19 (Interaction of CSP and IRIs): How are non-ASCII characters handled in CSP
webappsec-ISSUE-18 (CSP as risk assessment score): Use CSP to report app risk and compatibility with user specified restrictions
webappsec-ISSUE-17 (Extension compat): CSP should take into account extensions which modify content
webappsec-ISSUE-16 (CSP informs client, cannot restrict it): Editorial: CSP cannot dictate client behavior, only inform it
Re: New clickjacking research published
[webappsec] Major update to UI Safety
script-tag with html template-content
- Re: script-tag with html template-content
- RE: script-tag with html template-content
- RE: script-tag with html template-content