"Requirements for Powerful Features" strawman.
- Martin Thomson (Tuesday, 25 November)
- Chris Palmer (Tuesday, 25 November)
- Martin Thomson (Tuesday, 25 November)
- Mark Nottingham (Sunday, 23 November)
- Nottingham, Mark (Sunday, 23 November)
- Mike West (Saturday, 22 November)
- Mark Watson (Friday, 21 November)
- Mike West (Friday, 21 November)
- Mark Watson (Friday, 21 November)
- Mike West (Friday, 21 November)
- Mark Watson (Friday, 21 November)
- Mike West (Friday, 21 November)
- Mark Watson (Friday, 21 November)
- Mike West (Friday, 21 November)
- Anne van Kesteren (Friday, 21 November)
- Mark Watson (Thursday, 20 November)
- Mark Nottingham (Thursday, 20 November)
- Mike West (Thursday, 20 November)
- Brad Hill (Thursday, 20 November)
- Mike West (Thursday, 20 November)
- Brad Hill (Thursday, 20 November)
- Chris Palmer (Thursday, 20 November)
- Mike West (Thursday, 20 November)
- Brad Hill (Thursday, 20 November)
- Mike West (Thursday, 20 November)
[Bug 27291] New: Referrer: Consider a mechanism to specify a referrer URL.
[Bug 27302] New: Define an elaboration of #may-document-use-powerful-features that checks ancestor browsing contexts
[Bug 27341] New: consider replacing integrity-metatata ABNF production with a precise prose definition of the datatype/microsyntax
[CSP] <meta> clarifications
[CSP] Additional report field: report-only: "true|false"
[CSP] An outline of a taxonomy of CSP directives
[CSP] Clarifications on nonces
[CSP] Clarifications regarding the HTTP LINK Header
- Anne van Kesteren (Tuesday, 18 November)
- Deian Stefan (Tuesday, 18 November)
- Brian Smith (Tuesday, 18 November)
- Brad Hill (Tuesday, 18 November)
- Deian Stefan (Tuesday, 18 November)
- Brad Hill (Monday, 17 November)
- Ilya Grigorik (Friday, 14 November)
- Anne van Kesteren (Friday, 14 November)
- Brian Smith (Friday, 14 November)
- Ilya Grigorik (Thursday, 13 November)
- Boris Zbarsky (Thursday, 13 November)
- Brian Smith (Thursday, 13 November)
- Ilya Grigorik (Wednesday, 12 November)
- Brian Smith (Wednesday, 12 November)
- Ilya Grigorik (Wednesday, 12 November)
- Brian Smith (Tuesday, 11 November)
- Ilya Grigorik (Tuesday, 11 November)
- Brian Smith (Sunday, 9 November)
[CSP] Consistency of CSP hash-source with SRI regarding secure origins
[CSP] Implementer differences: window.open
[CSP] may we have script-ancestors to protect JSONP call
[CSP] outbound links
[CSP] PING-- CSP vs. Fetch
[CSP] prevent 401 attach
[CSP] Problems with frame-ancestors; X-Frame-Options not obsolete?
[CSP] Relative/absolute hostname matching
[CSP] URI Query part matching
[CSP] URI/IRI normalization and comparison
- Brian Smith (Tuesday, 18 November)
- Anne van Kesteren (Wednesday, 12 November)
- Brian Smith (Wednesday, 12 November)
- Anne van Kesteren (Wednesday, 12 November)
- Brian Smith (Tuesday, 11 November)
- Brian Smith (Tuesday, 11 November)
- Brian Smith (Tuesday, 11 November)
- Anne van Kesteren (Monday, 10 November)
- Anne van Kesteren (Monday, 10 November)
- Brian Smith (Monday, 10 November)
- Brian Smith (Monday, 10 November)
- Anne van Kesteren (Friday, 7 November)
- Brian Smith (Thursday, 6 November)
[CSP] violation reports for sandbox
[MIX] 4.5 User Controls
[MIX] HTTPS -> non-HTTPS redirects
[MIX] Initial feedback on Mixed Content
- Jim Manico (Friday, 28 November)
- Jeffrey Walton (Friday, 28 November)
- Anne van Kesteren (Tuesday, 25 November)
- Mike West (Tuesday, 25 November)
- Brian Smith (Monday, 24 November)
- Mike West (Monday, 24 November)
- Mike West (Sunday, 23 November)
- Brian Smith (Friday, 21 November)
- Mike West (Tuesday, 18 November)
- Brian Smith (Tuesday, 18 November)
- Brian Smith (Tuesday, 18 November)
- Jake Archibald (Friday, 14 November)
- Mike West (Friday, 14 November)
- Brian Smith (Friday, 14 November)
[MIX] Interaction between HSTS and mixed content blocking
[MIX] Language improvement for authenticated origin defintiion
[MIX] link rel=icon
[MIX] Modifications to script APIs
[MIX] RfC: WebAppSec's Last Call Working Draft of Mixed Content; deadline December 11
[power] simplify 2.1
[SRI] Escaping mixed-content blocking for video distribution
- Mark Watson (Tuesday, 18 November)
- Brad Hill (Monday, 17 November)
- Chris Palmer (Friday, 14 November)
- Anne van Kesteren (Thursday, 13 November)
- Mike West (Thursday, 13 November)
- Anne van Kesteren (Thursday, 13 November)
- Mike West (Thursday, 13 November)
- Anne van Kesteren (Thursday, 13 November)
- Mark Watson (Thursday, 13 November)
- Brian Smith (Thursday, 13 November)
- Mark Watson (Wednesday, 12 November)
- Brian Smith (Wednesday, 12 November)
- Mark Watson (Wednesday, 12 November)
- Mark Watson (Wednesday, 12 November)
- Brad Hill (Wednesday, 12 November)
- Mark Watson (Wednesday, 12 November)
- Anne van Kesteren (Wednesday, 12 November)
- Brad Hill (Wednesday, 12 November)
- Mark Watson (Wednesday, 12 November)
- Mark Watson (Wednesday, 5 November)
- Adam Langley (Wednesday, 5 November)
- Mark Watson (Wednesday, 5 November)
- Mark Watson (Wednesday, 5 November)
- Adam Langley (Monday, 3 November)
- Mike West (Monday, 3 November)
- Mark Watson (Monday, 3 November)
[SRI] may only be used in documents in secure origins
- Pete Freitag (Wednesday, 5 November)
- Brian Smith (Wednesday, 5 November)
- Brian Smith (Wednesday, 5 November)
- Chris Palmer (Wednesday, 5 November)
- Anne van Kesteren (Wednesday, 5 November)
- Devdatta Akhawe (Wednesday, 5 November)
- Brian Smith (Wednesday, 5 November)
- Michal Zalewski (Wednesday, 5 November)
- Chris Palmer (Wednesday, 5 November)
- Michal Zalewski (Tuesday, 4 November)
- Tanvi Vyas (Tuesday, 4 November)
- Chris Palmer (Tuesday, 4 November)
- Joel Weinberger (Tuesday, 4 November)
- Frederik Braun (Monday, 3 November)
- Pete Freitag (Monday, 3 November)
[SRI] To trust or not to trust a CDN
- Frederik Braun (Friday, 21 November)
- Eduardo Robles Elvira (Thursday, 20 November)
- Brian Smith (Thursday, 20 November)
- Brian Smith (Thursday, 20 November)
- Frederik Braun (Thursday, 20 November)
- Brad Hill (Thursday, 20 November)
- Brian Smith (Thursday, 20 November)
- Devdatta Akhawe (Sunday, 9 November)
- Brian Smith (Thursday, 6 November)
- Devdatta Akhawe (Thursday, 6 November)
- Brian Smith (Wednesday, 5 November)
- Brian Smith (Wednesday, 5 November)
- Brian Smith (Wednesday, 5 November)
[webappsec] "operator eval"
[webappsec] Agenda for Teleconference, Monday 03 Nov 2014
[webappsec] Agenda for Teleconference, Monday 17 Nov 2014
[webappsec] Draft charter for review
[webappsec] New W3C process and Last Call
[webappsec] Rechartering: additional cookie data
[webappsec] Rechartering: COWL
[webappsec] Rechartering: Credential Management API
[webappsec] Rechartering: CSP Level 3
[webappsec] Rechartering: Entry Point Regulation (EPR)
[webappsec] Rechartering: force secure-only child browsing contexts
[webappsec] Rechartering: MIME-type sniffing
[webappsec] Rechartering: sandboxed cross-origin workers
[webappsec] Rechartering: Secure Introduction of Internet-Connected Things
[webappsec] Rechartering: Sub-Origins
- Nottingham, Mark (Sunday, 23 November)
- Brian Smith (Tuesday, 11 November)
- Michal Zalewski (Tuesday, 11 November)
- Brad Hill (Monday, 10 November)
- Brian Smith (Monday, 10 November)
- Brad Hill (Monday, 10 November)
- David Bruant (Monday, 10 November)
- Devdatta Akhawe (Monday, 10 November)
- Michal Zalewski (Monday, 10 November)
- Mike West (Monday, 10 November)
- David Bruant (Monday, 10 November)
- Deian Stefan (Monday, 10 November)
- Devdatta Akhawe (Monday, 10 November)
- Brad Hill (Monday, 10 November)
[webappsec] Rechartering: Web Authentication v.Next
[webappsec] Rechartering: Write-Only Form Elements
[webappsec] TPAC summary
Avoiding syncronous manifest requests in EPR
Bug tracking
Call for consensus to move forward with proposed rechartering of WebAppSec WG
Call for Exclusions (Update): Referrer Policy
Call for Exclusions: Mixed Content
CfC: Mixed Content to Last Call?
CfC: Publish a FPWD of "Requirements for Powerful Features"
Clarification of CSP sandbox and workers
CSP3: DOM API Strawman
CSP: Problems with referrer and reflected-xss
Early morning thoughts on referrers.
Frame access
Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
Netflix, MSE, and EME
Rechartering: Permissions API
Referrer Policy: Same-origin URIs
- Devdatta Akhawe (Monday, 10 November)
- Brian Smith (Monday, 10 November)
- Devdatta Akhawe (Sunday, 9 November)
- Brian Smith (Sunday, 9 November)
- Devdatta Akhawe (Sunday, 9 November)
- Michal Zalewski (Saturday, 8 November)
- Jim Manico (Saturday, 8 November)
- Michal Zalewski (Saturday, 8 November)
- Michal Zalewski (Saturday, 8 November)
- Michal Zalewski (Saturday, 8 November)
- Devdatta Akhawe (Saturday, 8 November)
RfC: WebAppSec's Last Call Working Draft of Mixed Content; deadline December 11
Should CSP affect a Notification icon?
- Jim Manico (Monday, 10 November)
- Anne van Kesteren (Monday, 10 November)
- Anne van Kesteren (Monday, 10 November)
- Daniel Veditz (Monday, 10 November)
- Devdatta Akhawe (Monday, 10 November)
- Deian Stefan (Monday, 10 November)
- Brian Smith (Monday, 10 November)
- Jim Manico (Monday, 10 November)
- Daniel Veditz (Monday, 10 November)
- Brian Smith (Sunday, 9 November)
- Brian Smith (Sunday, 9 November)
- Daniel Veditz (Sunday, 9 November)
snapshots in CfC Re: CfC: Publish a FPWD of "Requirements for Powerful Features"
some testing on workers and sandbox
TPAC survey
webappsec-ACTION-200: Investigate git issue tooling with other w3c groups
webappsec-ACTION-201: Add permissions api to draft charter
webappsec-ACTION-202: Issue cfc on new draft charter
webappsec-ACTION-203: Raise issue for sri large object /streaming integrity
webappsec-ACTION-204: Reply to mark watson that 1/2 of his issue is a last call comment to mix
webappsec-ACTION-205: Does link really violate csp guarantees?
webappsec-ACTION-206: Reply on referrer suggest imperative policy controls in serviceworker
webappsec-ACTION-207: Raise definition of sandboxed worker in html spec
webappsec-ISSUE-69 (Overt channel control in CSP): Consider directives to manage postMessage and external navigation of iframes [CSP Next]
webappsec-ISSUE-70 (Using ni:/// as CSP source): Investigate using ni:/// as a CSP source expression [CSP Next]
webappsec-ISSUE-71 (JSONP directives): Consider directives in CSP Level 3 to reduce attack surface of legacy JSONP interaces [CSP Level 3]
webappsec-ISSUE-72 (Streaming Integrity): How to apply integrity verification to large / streaming downloads [Subresource Integrity Level 2]
WebRTC Security Assessment
Last message date: Friday, 28 November 2014 17:11:31 UTC