webappsec-ISSUE-55 (input-protection and seamless iframes): How to handle seamless flag for input-protection policies? [UI Security]
[webappsec] UISecurity input protection: same origin or same document?
[webappsec] New SVG examples for UISecurity obstruction check
Are CSP directives case insensitive?
[Bug 23654] New: Point out that Access-Control-Allow-Origin:* is safe for servers not behind a firewall
[Bug 23653] New: Advice on CORS and caches
CSP and cookie header management
Content-Security-Policy: referrer always
Agenda for October 22, 2013 Teleconference
'referrer' directive strawman.
Re: Updated script hash proposal (non spec text)
[webappsec] new editor's draft of UISecurity
CSP script hashes, inline and src'd
Reminder: Recharter out for review through Oct. 21
[webappsec] Handling unsafe UI events
FYI: RFC 7034 on HTTP Header Field X-Frame-Options
Re: [CORS] Clarifying the term "user credentials"
[webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
- Re: [webappsec] ISSUE-53: UISecurity input-protection heuristic for composited rendering
Behavior when default-src is missing from a CSP
proposal: move frame-options directive out of UI safety spec into CSP 1.1
[webappsec] Agenda for 8-Oct-2013 Teleconference
ERRATA CORRIGE Actual vote and regrets (was Re: [webappsec] POLL: Getting CSP 1.1 to LCWD)
Actual vote and regrets (was Re: [webappsec] POLL: Getting CSP 1.1 to LCWD)
Scripts from Strings: Where is the line?
Actual Poll vote (was: Reminder: please send your preferences (was: POLL: Getting CSP 1.1 to LCWD))
[webappsec] Reminder: please send your preferences
- Re: [webappsec] Reminder: please send your preferences
- Re: [webappsec] Reminder: please send your preferences
- Re: [webappsec] Reminder: please send your preferences
- RE: [webappsec] Reminder: please send your preferences
Re: [Workers] CSP and SharedWorkers
Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- Re: [webappsec] POLL: Getting CSP 1.1 to LCWD
- RE: [webappsec] POLL: Getting CSP 1.1 to LCWD