public-webappsec@w3.org from June 2013 by subject

[Bug 22256] New: Add a note regarding first line of defense.

[filter-effects][css-masking] Move security model for resources to CSP

[webappsec-testsuite] New test server for CSP testing.

[webappsec] CSP reporting and sandbox directive

[webappsec] No TPAC meeting in Shenzhen

[webappsec] plugin-types directive for CLSIDs in IE

[whatwg] Cross-Origin Cookies Sharing Proposal

Agenda for June 4 Teleconference

broadening default-src semantics

Content Security Policy

Content Security Policy 1.1 : script-nonce or script-hash

Content Security Policy: inline style blocking, CSSOM and unsafe-eval

CORS Allow header in preflight response

Cross-domain information leak with UI Security Directives

Cross-Origin Cookies Sharing Proposal

CSP: connect-src

CSP: error handling

CSP: origin from a URL

cspBuilder Wizard

Fetching contexts

Fwd: webappsec tests moved to GitHub

meta restrictions (ACTION 109)

policy-uri proposal (ACTION 97)

Possible bug in algorithm to match a source expression?

Specifying nonce-source for every directive

Supporting base64 in nonce-value

Today's call cancelled

Web Developer Security 1.0 - Training Tues 6/18

webappsec tests moved to GitHub

Last message date: Saturday, 29 June 2013 02:07:06 UTC