[CSP] Implementer differences: window.open
Implementer differences
[MIX] 6.1 May browsing context use powerful features?
[MIX] 5.1 Does settings object restrict mixed content?
- Re: [MIX] 5.1 Does settings object restrict mixed content?
[MIX] 4.5 User Controls
[MIX] Normative statements in 4.1 Resource Fetching
[MIX] Modifications to script APIs
Permission that spans browsing contexts
CfC: Mixed Content to Last Call?
Minimum viable SRI?
FYI: Starting on CSP Next.
[webappsec] do we want a way to hash data: and blob: uris?
[SRI] To trust or not to trust a CDN
- Re: [SRI] To trust or not to trust a CDN
- Re: [SRI] To trust or not to trust a CDN
- Re: [SRI] To trust or not to trust a CDN
- Re: [SRI] To trust or not to trust a CDN
[webappsec] TPAC agenda changes
[webappsec] F2F at TPAC on hold
No-context ACTION emails are confusing
webappsec-ISSUE-69 (Overt channel control in CSP): Consider directives to manage postMessage and external navigation of iframes [CSP Next]
[webappsec] survey results
webappsec-ACTION-199: Keep topic of internet/intranet connectivity and https on the w3c radar
webappsec-ACTION-198: Take bookmarklets discussion back to the list
webappsec-ACTION-197: Schedule an ad-hoc at TPAC 2014 (+wseltzer, +plh, +robin, +tbl?)
webappsec-ACTION-196: Remove intranet/internet section from Mixed Content spec
webappsec-ACTION-195: Respond to Hatter Jiang on JSONP directives - under consideration for v.Next
webappsec-ACTION-194: Respond to Hatter Jiang on 401 attach
webappsec-ISSUE-68 (401 prompting by subresources): How to manage 401 phishing prompts by subresources
webappsec-ACTION-193: Respond to Brian Smith on referrer-policy
webappsec-ACTION-192: Evaluate control over nesting depth.
webappsec-ACTION-191: Inconsistency in source hash description
webappsec-ACTION-190: Is reflected-xss directive at risk?
[webappsec] TPAC living agenda
[CSP] Inconsistency between Source hash introduction and Source hash usage
[webappsec] updated (but still draft) TPAC agenda
Service workers, dedicated workers, and the environment settings object
Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- RE: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- RE: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- RE: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
- Re: Frame Ancestors and Referrer (Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note)
[referrer] HTTPS->HTTP
[integrity] Different ways to associate integrity information
[webappsec] Rough and preliminary TPAC agenda for WebAppSec
[MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
- Re: [MIX] Is origin an authenticated origin?
[MIX] feedback
[webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note
- Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note
- Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note
- Re: [webappsec] Call for Consensus: Stop work on Content Security Policy 1.0, transition to WG Note
[webappsec] Call for Consensus: CSP Level 2 to Candidate Recommendation
[webappsec] Survey on WebAppSec Charter v.Next work
"Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
- Re: "Secure Introduction of Internet-Connected Things" (was Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT)
referrer policy questions
[webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT
- Re: [webappsec] Agenda for MONDAY Teleconference 2014-10-20, 12:00 PDT
[webappsec] Topics for Rechartering
NTP vs. HSTS
[Credential Management]: Tiny prototype to play around with.
[webappsec] draft new WG home page
Allow dynamically inserted <script>-Tags from trustworthy Scripts
- Re: Allow dynamically inserted <script>-Tags from trustworthy Scripts
- Re: Allow dynamically inserted <script>-Tags from trustworthy Scripts
- Re: Allow dynamically inserted <script>-Tags from trustworthy Scripts