[Bug 21608] New: 7.2 "Resource Sharing Check" does not specify how to handle a space separated list in Access-Control-Allow-Origin
[filter-effects][css-masking] Move security model for resources to CSP
- Dirk Schulze (Thursday, 11 April)
- Anne van Kesteren (Thursday, 11 April)
- Dirk Schulze (Wednesday, 10 April)
- Robert O'Callahan (Wednesday, 10 April)
- Anne van Kesteren (Wednesday, 10 April)
- Robert O'Callahan (Wednesday, 10 April)
- Daniel Holbert (Tuesday, 9 April)
- Dirk Schulze (Tuesday, 9 April)
- Anne van Kesteren (Tuesday, 9 April)
- Dirk Schulze (Tuesday, 9 April)
- Robert O'Callahan (Tuesday, 9 April)
- Robert O'Callahan (Tuesday, 9 April)
- Anne van Kesteren (Tuesday, 9 April)
- Robert O'Callahan (Tuesday, 9 April)
- Anne van Kesteren (Tuesday, 9 April)
- Bjoern Hoehrmann (Tuesday, 9 April)
- Anne van Kesteren (Monday, 8 April)
- Dirk Schulze (Monday, 8 April)
- Anne van Kesteren (Monday, 8 April)
- Dirk Schulze (Monday, 8 April)
- Anne van Kesteren (Monday, 8 April)
- Dirk Schulze (Monday, 8 April)
- Anne van Kesteren (Monday, 8 April)
- Bjoern Hoehrmann (Saturday, 6 April)
- Anne van Kesteren (Saturday, 6 April)
- Dirk Schulze (Saturday, 6 April)
- Anne van Kesteren (Saturday, 6 April)
- Dirk Schulze (Friday, 5 April)
- Anne van Kesteren (Friday, 5 April)
- Anne van Kesteren (Friday, 5 April)
- Dirk Schulze (Friday, 5 April)
- Mike West (Friday, 5 April)
- Anne van Kesteren (Friday, 5 April)
- Dirk Schulze (Friday, 5 April)
[webapppsec] CfC: UI Security to WD
[webappsec] Call for Consensus: CSP 1.1 to FPWD
[webappsec] Call today CANCELLED
[webappsec] CSP 1.0 bug? button type=image and img-src
[webappsec] Final logistics for F2F April 25-26
[webappsec] Friday test jam preparation
[webappsec] Please register for April F2F
[webappsec] Proposed agenda for next week's F2F
[webappsec] remote participation resources
[webappsec] Tomorrow's teleconference CANCELLED
ACTION-115: Proposal for handling srcdoc
ACTION-120: Proposal for handling custom elements
ACTION-129: plugin-types inherits into plugin documents
API coordination with TC39 (ECMAscript)
Column numbers in violation reports.
CORS Allow header in preflight response
CSP 1.0 copy&paste error
CSP and `picture`
CSP and innerHTML
CSP when external script loads another external script?
CSP within frame constructed with "data:" URI?
CSP, Remote-Only Mode, and Browser Extensions
Fwd: [filter-effects][css-masking] Move security model for resources to CSP
Minor edits to CSP 1.1
Moving our tests to GitHub (same as WebApps)
Please register this week for April 25-26 F2F
Regrets (Re: [webappsec] remote participation resources)
script-src 'self' https://example.com 'nonce-nc34908WECd8f3'
Trimming the SecurityPolicy DOM interface
webappsec-ISSUE-46 (Does nonce make CSP header security-sensitive): Does inclusion of things like nonce make CSP a sensitive header? [CSP 1.1]
webappsec-ISSUE-47: Revisit combinations of header and meta tags [CSP 1.1]
webappsec-ISSUE-48 (base uri): injection of a <base> tag to change effective location of relative resources [CSP 1.1]
webappsec-ISSUE-49: add http response code to report? [CSP 1.1]
webappsec-ISSUE-50: plugin-type directive and media source list for IE CLSID guids [CSP 1.1]
webappsec-ISSUE-51: How to handle externally defined <element> with <link rel=import>
webappsec-ISSUE-52 (unsafe DOM API): unsafe attribute requires every handler to check [UI Security]
webappsec-ISSUE-53 (UI Security model for composited drawing models): UI Security model for composited drawing models [UI Security]
Last message date: Tuesday, 30 April 2013 21:01:51 UTC