[webappsec] CSP: are blob uri's really just origin='self'?
- Re: [webappsec] CSP: are blob uri's really just origin='self'?
CORS to PR
Agenda for 8/27/13 Conference Call
CSP 1.1 and image loading elements/attributes
[CORS] Understanding the definition of simple headers
- Re: [CORS] Understanding the definition of simple headers
- Re: [CORS] Understanding the definition of simple headers
Proposed CSRF countermeasure
[webappsec] Proposed Agenda for 13-Aug-2013 WebAppSec WG Teleconference
ACTION-147 RFC script-hash proposal v2
Audio & security
Re: CSP 1.1: Nonce-source and unsafe-inline
Re: [webappsec + webapps] CORS to PR plans
- Re: [webappsec + webapps] CORS to PR plans
- Re: [webappsec + webapps] CORS to PR plans
- Re: [webappsec + webapps] CORS to PR plans
- Re: [webappsec + webapps] CORS to PR plans
Re: Supporting base64 in nonce-value
Sub-origins
Including the Javascript stack trace in the ContentSecurityPolicy report
- Re: Including the Javascript stack trace in the ContentSecurityPolicy report
- Re: Including the Javascript stack trace in the ContentSecurityPolicy report
- Re: Including the Javascript stack trace in the ContentSecurityPolicy report