CORS: Requirement for HTTP 200 response on preflight is not web-compatible and doesn't seem to be interoperably implemented
- Re: CORS: Requirement for HTTP 200 response on preflight is not web-compatible and doesn't seem to be interoperably implemented
- Re: CORS: Requirement for HTTP 200 response on preflight is not web-compatible and doesn't seem to be interoperably implemented
Re: Restricting <base> URLS via CSP
ISSUE-44: Same-origin policy identity query via script-hash. issue is you do a third party inline script with a known script-hash. if it succeeds, you know that the target was as expected, even though you can't read it
Action-92: Propose spec text to resolve ISSUE-32
[webappsec] March 12 teleconference CANCELLED due to conflict with IETF
[webappsec] minutes available
Feedback on UI Safety draft
Agenda for Feb 26 Call
FTC v HTC America
Call for Exclusions (Update): User Interface Safety Directives for Content Security Policy
[CORS] list max-age as algorithm parameter
[Bug 21013] New: Credentials and HTTP authentication
[Bug 21012] New: Add more text on Vary
[CORS] typos
Do we need Connectors between javascript and security software at personal device?
Proposal for script-hash directive in CSP 1.1
Why no fragment part in CSP-report document-uri?
W3C account
[webappsec] WG satisfaction survey
No scheme in policy: Errors for either scheme
Re: ISSUE-32: Do we specify that path-specificity applies only to hierarchical URI schemes?
[webappsec] UI Security, allow-from values
[webappsec] Agenda for 12-Feb-2013 WebAppSec Teleconference
Help needed (or not?) (was ISSUE-27: Implementation concern on how to enforce display-time : should we provide more advice on how to do this efficiently?)
CSP and inline styles
RE: ISSUE-38: Discuss no-mixed-content directive
Blank blocked-uris
CSP script hashes
- Re: CSP script hashes
- Re: CSP script hashes
- Re: CSP script hashes
- Re: CSP script hashes