public-webappsec@w3.org from September 2014 by subject

[CSP] compatibility between CSP1.1 and CSP2

[CSP] Compatibility with 1.1 or 1.0

[CSP] kill or delay child-src?

[CSP] may we have script-ancestors to protect JSONP call

[CSP] Regarding style-src unsafe-eval and CSSOM

[CSP] why we do it!

[Integrity] hash in HTTP header field

[Integrity] Some comments on Cross-Origin leakage and content types

[Integrity] Some comments on Subresource Integrity draft

[MIX] Feedback on the private origin & self-signed certificate requirements

[webappsec] Agenda: WebAppSec WG Teleconference 10-September-2014 08:00 PDT

[webappsec] Changing my organizational hats

[webappsec] Concluding the Last Call period for CSP Level 2

[webappsec] Poll: new teleconference time

[webappsec] Re-chartering discussions at TPAC

[webappsec] tomorrow's call CANCELLED

CfC: Publish a new WD of MIX.

CSP for WebRTC

CSP Level 2 last call comment

CSP reports on eval() and inline

CSP: Minimum cipher strength

Defining secure-enough origins.

Feature-detecting a Content Security Policy

Fwd: Verified Javascript for WebAppSec re-chartering?

HTML Imports vs unsafe-inline

ISSUE-65: Does "no referrer" specify a state or is it a token? is a token with a space problematic?

Looking for a home for a proposed Credential Management API.

Proposal: not-a-scheme digest URI scheme, with graceful degradation

Proposal: Prefer secure origins for powerful new web platform features

Redirects and HSTS

Review request for a few WebAppSec specs.

SRI: <a> vs integrity

Subresource integrity in Chromium

Verified Javascript for WebAppSec re-chartering?

webappsec-ISSUE-67: WebRTC via 'connect-src'?

XMLHttpRequest. Support for "OPTIONS *" method.

Last message date: Monday, 29 September 2014 14:01:40 UTC