public-webappsec@w3.org from September 2013 by thread

[webappsec] POLL: Getting CSP 1.1 to LCWD Brad Hill (Monday, 30 September)

CSP and Fetch Anne van Kesteren (Monday, 30 September)

[CORS] Clarifying the term "user credentials" Monsur Hossain (Friday, 27 September)

[Workers] CSP and SharedWorkers Kyle Huey (Thursday, 26 September)

[Bug 23357] New: Subverting CSP policies for browser add-ons (extensions). bugzilla@jessica.w3.org (Wednesday, 25 September)

Fwd: Cross-Origin Resource Sharing - text Anne van Kesteren (Tuesday, 24 September)

[webappsec] Charter review Brad Hill (Tuesday, 24 September)

[webappsec] Sep 24 teleconference CANCELLED Brad Hill (Tuesday, 24 September)

Attempt to use CSP - Questions Aymeric Vitte (Friday, 20 September)

[CORS] Typo in Preflight Request step 10 Adam Roben (Thursday, 19 September)

CSP 1.0: s/caller/legacycaller/ Dominique Hazael-Massieux (Friday, 20 September)

Updated script hash proposal (non spec text) Neil Matatall (Thursday, 19 September)

Plan to transition Web Notifications spec to LCWD Jon Lee (Friday, 13 September)

[webappsec] LC for Web Notifications Brad Hill (Thursday, 12 September)

[webappsec] FW: Zakim - no coverage on 20, 23, and 24 September Hill, Brad (Thursday, 12 September)

Serialized suborigins Joel Weinberger (Wednesday, 11 September)

Adding cookie scope to CSP Nottingham, Mark (Tuesday, 10 September)

[webappsec] Draft Agenda for 10-Sep-2013 Teleconference Brad Hill (Tuesday, 10 September)

[webappsec] Proposal: Closing the feature set of CSP 1.1 Brad Hill (Tuesday, 10 September)

Re: Sub-origins Devdatta Akhawe (Tuesday, 3 September)

Re: [webappsec] CSP: are blob uri's really just origin='self'? Anne van Kesteren (Tuesday, 3 September)

[CORS] Security models and confusion about credentials Austin William Wright (Sunday, 1 September)

Last message date: Monday, 30 September 2013 23:23:50 UTC