Monday, 30 June 2014
- Re: CSP: 'no-external-navigation'?
- Re: PFWG comments on User Interface Security Directives for Content Security Policy
- Re: [MIX]: Can we distinguish between images loader via `<picture>`/`srcset` and `<img>`?
- Re: CSP: 'no-external-navigation'?
- Re: CSP: 'no-external-navigation'?
- CSP: 'no-external-navigation'?
- Re: CSP wildcard host matching
- Re: Isolated Web Components for a more secure web
- Re: [MIX]: Can we distinguish between images loader via `<picture>`/`srcset` and `<img>`?
- Re: [MIX]: Can we distinguish between images loader via `<picture>`/`srcset` and `<img>`?
- Re: [MIX]: Can we distinguish between images loader via `<picture>`/`srcset` and `<img>`?
- Re: [MIX]: Can we distinguish between images loader via `<picture>`/`srcset` and `<img>`?
- [MIX]: Can we distinguish between images loader via `<picture>`/`srcset` and `<img>`?
Saturday, 28 June 2014
Monday, 30 June 2014
- Re: CSP wildcard host matching
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: CSP wildcard host matching
Sunday, 29 June 2014
- Re: CSP wildcard host matching
- Re: CSP wildcard host matching
- Re: CSP wildcard host matching
- Re: CSP wildcard host matching
- Re: CSP wildcard host matching
Saturday, 28 June 2014
- [MIX] blob URLs
- Re: [blink-dev] Proposal: Prefer secure origins for powerful new web platform features
- Re: [blink-dev] Proposal: Prefer secure origins for powerful new web platform features
- Re: [blink-dev] Proposal: Prefer secure origins for powerful new web platform features
- Re: [blink-dev] Proposal: Prefer secure origins for powerful new web platform features
- Re: [blink-dev] Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: [blink-dev] Proposal: Prefer secure origins for powerful new web platform features
- Re: Proposal: Prefer secure origins for powerful new web platform features
Friday, 27 June 2014
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Proposal: Prefer secure origins for powerful new web platform features
Thursday, 26 June 2014
- Re: [CSP] Additional report field: report-only: "true|false"
- Re: [CSP] Additional report field: report-only: "true|false"
- Re: [CSP] Additional report field: report-only: "true|false"
- [CSP] Additional report field: report-only: "true|false"
Wednesday, 25 June 2014
- Re: CfC to publish FPWD of Mixed Content.
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- CfC to publish FPWD of Mixed Content.
Tuesday, 24 June 2014
- Re: Reducing reporting noise
- Re: CfC to publish a LCWD of CSP 1.1
- Re: Naming things: CSP 1.1 -> CSP level 2?
- Re: Naming things: CSP 1.1 -> CSP level 2?
- Re: Naming things: CSP 1.1 -> CSP level 2?
- Re: Naming things: CSP 1.1 -> CSP level 2?
- Re: Naming things: CSP 1.1 -> CSP level 2?
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- Re: Naming things: CSP 1.1 -> CSP level 2?
- Naming things: CSP 1.1 -> CSP level 2?
- Re: CfC to publish a LCWD of CSP 1.1
Friday, 20 June 2014
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: Reducing reporting noise
- Re: CfC to publish a LCWD of CSP 1.1
- Re: Reducing reporting noise
Thursday, 19 June 2014
- Re: Reducing reporting noise
- Reducing reporting noise
- PFWG comments on User Interface Security Directives for Content Security Policy
Wednesday, 18 June 2014
- Re: CfC to publish a LCWD of CSP 1.1
- webappsec-ISSUE-62: is reflected-xss at risk?
- ISSUE-61: Should we mark referrer and reflected-xss as at risk in csp 1.1 lcwd?
- Re: CSP: Problems with referrer and reflected-xss
Tuesday, 17 June 2014
- Re: Regrets ( [webappsec] WebAppSec WG Teleconference Agenda 18-June-2014 )
- [webappsec] WebAppSec WG Teleconference Agenda 18-June-2014
- Call for Exclusions (Update): Subresource Integrity
- Re: CSP: Problems with referrer and reflected-xss
Monday, 16 June 2014
- Re: CSP: Problems with referrer and reflected-xss
- Re: [integrity] The noncanonical-src attribute
- Re: [MIX]: Move specifics to a non-normative section/document? (Re: "Mixed Content" draft up for review.)
- Re: CSP: Problems with referrer and reflected-xss
- Re: CSP: Problems with referrer and reflected-xss
- Re: CSP: Problems with referrer and reflected-xss
Sunday, 15 June 2014
Friday, 13 June 2014
- Re: [integrity] The noncanonical-src attribute
- Re: [MIX]: Move specifics to a non-normative section/document? (Re: "Mixed Content" draft up for review.)
- Re: [integrity] The noncanonical-src attribute
- [integrity] The noncanonical-src attribute
- Re: CSP: Problems with referrer and reflected-xss
- Re: CSP: Problems with referrer and reflected-xss
- Re: CSP: Problems with referrer and reflected-xss
- Re: [MIX]: Move specifics to a non-normative section/document? (Re: "Mixed Content" draft up for review.)
- CSP: Problems with referrer and reflected-xss
Thursday, 12 June 2014
- Re: Header Policy Vs. Meta tag policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
Wednesday, 11 June 2014
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
Thursday, 12 June 2014
Wednesday, 11 June 2014
- Re: Standardize referrer policy
- RE: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Header Policy Vs. Meta tag policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Re: Standardize referrer policy
- Standardize referrer policy
- Re: Header Policy Vs. Meta tag policy
- Re: Header Policy Vs. Meta tag policy
- Re: Header Policy Vs. Meta tag policy
- [Bug 26061] New: Improve consistency with CSP 1.1 w.r.t. add-on/extension semantics.
- Re: CfC to publish a LCWD of CSP 1.1
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: CfC to publish a LCWD of CSP 1.1
- Re: CfC to publish a LCWD of CSP 1.1
- CfC to publish a LCWD of CSP 1.1
- Re: Header Policy Vs. Meta tag policy
- Re: CSP: Block redirects by default?
- Re: [MIX]: "Assumed"/"Proven" Terminology.
- Re: Header Policy Vs. Meta tag policy
- Re: Header Policy Vs. Meta tag policy
Tuesday, 10 June 2014
- Re: Header Policy Vs. Meta tag policy
- Re: Header Policy Vs. Meta tag policy
- Re: Header Policy Vs. Meta tag policy
- Re: [MIX]: "Assumed"/"Proven" Terminology.
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Move specifics to a non-normative section/document? (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: Header Policy Vs. Meta tag policy
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
Monday, 9 June 2014
- Re: [MIX]: Move specifics to a non-normative section/document? (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Header Policy Vs. Meta tag policy
Friday, 6 June 2014
- Header Policy Vs. Meta tag policy
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: CSP sandboxing and workers
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- [MIX]: "Assumed"/"Proven" Terminology. (Re: [MIX]: Expand scope beyond TLS/non-TLS)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
Thursday, 5 June 2014
- Re: CSP sandboxing and workers
- Re: Discuss SVG and CSP for the June 5 SVG teleconference
- Re: Discuss SVG and CSP for the June 5 SVG teleconference
- Re: Discuss SVG and CSP for the June 5 SVG teleconference
- Re: CSP: Block redirects by default?
- Re: CSP: Block redirects by default?
- Re: CSP: Block redirects by default?
- Re: CSP: Block redirects by default?
- RE: CSP sandboxing and workers
- Re: CSP sandboxing and workers
- Re: Remove paths from CSP?
- Re: Remove paths from CSP?
- Re: [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: Remove paths from CSP?
- Re: [MIX] localhost should not be trusted
Wednesday, 4 June 2014
Thursday, 5 June 2014
- CSP: Block redirects by default?
- Re: Remove paths from CSP?
- Re: [CSP] enforcement on non text-html resources
- Re: [CSP] enforcement on non text-html resources
- RE: Agenda, 5 June 2014 SVG WG / WebAppSec WG telcon
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
Wednesday, 4 June 2014
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- Re: CSP sandboxing and workers
- Re: Agenda, 5 June 2014 SVG WG / WebAppSec WG telcon
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- Re: [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- [webappsec] Help build the CSP test suite at Test the Web Forward Portland, August 3
- Re: [CSP] enforcement on non text-html resources
- [CSP] enforcement on non text-html resources
- Re: CSP sandboxing and workers
- Re: Remove paths from CSP?
- Re: [MIX] Comments on draft Mixed Content spec
- Re: CSP, Fetch, and frame-ancestors
- Re: [MIX] Comments on draft Mixed Content spec
- Re: CSP, Fetch, and frame-ancestors
- Re: CSP, Fetch, and frame-ancestors
- [MIX]: Move specifics to a non-normative section/document? (Re: "Mixed Content" draft up for review.)
- Re: CSP, Fetch, and frame-ancestors
- [MIX]: Expand scope beyond TLS/non-TLS (Re: "Mixed Content" draft up for review.)
- Re: CSP, Fetch, and frame-ancestors
- Re: CSP, Fetch, and frame-ancestors
- Re: CSP, Fetch, and frame-ancestors
- Agenda, 5 June 2014 SVG WG / WebAppSec WG telcon
- Re: Discuss SVG and CSP for the June 5 SVG teleconference
- Re: CSP, Fetch, and frame-ancestors
- Re: CSP, Fetch, and frame-ancestors
- [MIX] Comments on draft Mixed Content spec
- Re: CSP, Fetch, and frame-ancestors
- Discuss SVG and CSP for the June 5 SVG teleconference
Tuesday, 3 June 2014
- Re: "Mixed Content" draft up for review.
- [webappsec] Teleconference Agenda: 04-Jun-2014
- Re: "Mixed Content" draft up for review.
- Re: Remove paths from CSP?
- Re: CORS and null
- Re: CORS and null
- Re: CORS and null
- Re: Remove paths from CSP?
- Re: CSP sandboxing and workers
- [MIX]: 'allow-from' header? (Re: "Mixed Content" draft up for review.)
- [MIX] Checking parent/top (Re: "Mixed Content" draft up for review.)
- Re: "Mixed Content" draft up for review - HSTS interworking
- Re: "Mixed Content" draft up for review.
- Re: CSP sandboxing and workers
- Re: "Mixed Content" draft up for review - HSTS primary purpose
Monday, 2 June 2014
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: CSP sandboxing and workers
- Re: CSP sandboxing and workers
- Re: CSP sandboxing and workers
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: Remove paths from CSP?
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: Remove paths from CSP?
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- Re: "Mixed Content" draft up for review.
- CORS and null
- Re: Remove paths from CSP?