public-webappsec@w3.org from April 2013 by subject

[Bug 21608] New: 7.2 "Resource Sharing Check" does not specify how to handle a space separated list in Access-Control-Allow-Origin

[filter-effects][css-masking] Move security model for resources to CSP

[webapppsec] CfC: UI Security to WD

[webappsec] Call for Consensus: CSP 1.1 to FPWD

[webappsec] Call today CANCELLED

[webappsec] CSP 1.0 bug? button type=image and img-src

[webappsec] Final logistics for F2F April 25-26

[webappsec] Friday test jam preparation

[webappsec] Please register for April F2F

[webappsec] Proposed agenda for next week's F2F

[webappsec] remote participation resources

[webappsec] Tomorrow's teleconference CANCELLED

ACTION-115: Proposal for handling srcdoc

ACTION-120: Proposal for handling custom elements

ACTION-129: plugin-types inherits into plugin documents

API coordination with TC39 (ECMAscript)

Column numbers in violation reports.

CORS Allow header in preflight response

CSP 1.0 copy&paste error

CSP and `picture`

CSP and innerHTML

CSP when external script loads another external script?

CSP within frame constructed with "data:" URI?

CSP, Remote-Only Mode, and Browser Extensions

Fwd: [filter-effects][css-masking] Move security model for resources to CSP

Minor edits to CSP 1.1

Moving our tests to GitHub (same as WebApps)

Please register this week for April 25-26 F2F

Regrets (Re: [webappsec] remote participation resources)

script-src 'self' https://example.com 'nonce-nc34908WECd8f3'

Trimming the SecurityPolicy DOM interface

webappsec-ISSUE-46 (Does nonce make CSP header security-sensitive): Does inclusion of things like nonce make CSP a sensitive header? [CSP 1.1]

webappsec-ISSUE-47: Revisit combinations of header and meta tags [CSP 1.1]

webappsec-ISSUE-48 (base uri): injection of a <base> tag to change effective location of relative resources [CSP 1.1]

webappsec-ISSUE-49: add http response code to report? [CSP 1.1]

webappsec-ISSUE-50: plugin-type directive and media source list for IE CLSID guids [CSP 1.1]

webappsec-ISSUE-51: How to handle externally defined <element> with <link rel=import>

webappsec-ISSUE-52 (unsafe DOM API): unsafe attribute requires every handler to check [UI Security]

webappsec-ISSUE-53 (UI Security model for composited drawing models): UI Security model for composited drawing models [UI Security]

Last message date: Tuesday, 30 April 2013 21:01:51 UTC