Thursday, 31 October 2013
- webappsec-ISSUE-55 (input-protection and seamless iframes): How to handle seamless flag for input-protection policies? [UI Security]
- Re: [webappsec] UISecurity input protection: same origin or same document?
- Re: [webappsec] UISecurity input protection: same origin or same document?
- [webappsec] UISecurity input protection: same origin or same document?
Wednesday, 30 October 2013
Monday, 28 October 2013
- Are CSP directives case insensitive?
- [Bug 23654] New: Point out that Access-Control-Allow-Origin:* is safe for servers not behind a firewall
- [Bug 23653] New: Advice on CORS and caches
Saturday, 26 October 2013
Friday, 25 October 2013
Wednesday, 23 October 2013
Tuesday, 22 October 2013
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- Content-Security-Policy: referrer always
- Agenda for October 22, 2013 Teleconference
- Re: [webappsec] Reminder: please send your preferences
- Re: 'referrer' directive strawman.
- Re: CSP script hashes, inline and src'd
Monday, 21 October 2013
- Re: CSP script hashes, inline and src'd
- Re: CSP script hashes, inline and src'd
- 'referrer' directive strawman.
- Re: proposal: move frame-options directive out of UI safety spec into CSP 1.1
- Re: CSP script hashes, inline and src'd
- Re: Updated script hash proposal (non spec text)
- Re: CSP script hashes, inline and src'd
- Re: proposal: move frame-options directive out of UI safety spec into CSP 1.1
- Re: proposal: move frame-options directive out of UI safety spec into CSP 1.1
- Re: CSP script hashes, inline and src'd
- Re: CSP script hashes, inline and src'd
Sunday, 20 October 2013
Saturday, 19 October 2013
- Re: CSP script hashes, inline and src'd
- Re: CSP script hashes, inline and src'd
- Re: CSP script hashes, inline and src'd
- Re: CSP script hashes, inline and src'd
- Re: CSP script hashes, inline and src'd
Friday, 18 October 2013
Wednesday, 16 October 2013
Tuesday, 15 October 2013
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- Reminder: Recharter out for review through Oct. 21
- Re: [webappsec] Handling unsafe UI events
Monday, 14 October 2013
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- [webappsec] Handling unsafe UI events
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- RE: RFC 7034 on HTTP Header Field X-Frame-Options
- FYI: RFC 7034 on HTTP Header Field X-Frame-Options
Friday, 11 October 2013
- Re: [CORS] Clarifying the term "user credentials"
- Re: [CORS] Clarifying the term "user credentials"
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
Thursday, 10 October 2013
- [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- Re: Behavior when default-src is missing from a CSP
- Re: Behavior when default-src is missing from a CSP
Wednesday, 9 October 2013
Tuesday, 8 October 2013
- Re: [webappsec] Reminder: please send your preferences
- Re: proposal: move frame-options directive out of UI safety spec into CSP 1.1
- proposal: move frame-options directive out of UI safety spec into CSP 1.1
- Re: [webappsec] Reminder: please send your preferences
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- [webappsec] Agenda for 8-Oct-2013 Teleconference
- Re: [webappsec] Reminder: please send your preferences
Monday, 7 October 2013
- RE: [webappsec] Reminder: please send your preferences
- Re: [webappsec] Reminder: please send your preferences
- Re: [webappsec] Reminder: please send your preferences
Saturday, 5 October 2013
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- ERRATA CORRIGE Actual vote and regrets (was Re: [webappsec] POLL: Getting CSP 1.1 to LCWD)
- Actual vote and regrets (was Re: [webappsec] POLL: Getting CSP 1.1 to LCWD)
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Scripts from Strings: Where is the line?
Friday, 4 October 2013
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] Reminder: please send your preferences
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Actual Poll vote (was: Reminder: please send your preferences (was: POLL: Getting CSP 1.1 to LCWD))
- [webappsec] Reminder: please send your preferences
Thursday, 3 October 2013
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
Wednesday, 2 October 2013
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
Tuesday, 1 October 2013
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- RE: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- RE: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [Workers] CSP and SharedWorkers
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD