CSP and mixed content
CORS and Caching (in reverse proxies / CDNs)
[webappsec] FW: Dan Veditz appointed co-chair of Web Application Security Working Group
CSP, Fetch, and frame-ancestors
Worker / SharedWorker directive
Re: CSP, Fetch, and Service Workers
Canceled: W3C WebAppSec WG Meeting
webappsec-ISSUE-60 (CSP and META): Injecting META tags can be an interesting bypass technique, possibly [CSP 1.2]
webappsec-ISSUE-59 (SVG rules for CSP): Figure out how to use CSP appropriately with SVG modes [CSP 1.1]
W3C WebAppSec WG Meeting
[webappsec] AGENDA: WebAppSec WG Teleconference 23-April-2014 08:00 PDT
CSP no-external-navigation
CSP, Blob Workers, and Firefox
[CSP] SVG-in-img implementation difference
- Re: [CSP] SVG-in-img implementation difference
Re: [integrity] What should we hash?
- Re: [integrity] What should we hash?
[Integrity] Comments/Questions on Subresource Integrity spec
- Re: [Integrity] Comments/Questions on Subresource Integrity spec
- Re: [Integrity] Comments/Questions on Subresource Integrity spec