Feature-detecting a Content Security Policy
[webappsec] Changing my organizational hats
Redirects and HSTS
- Re: Redirects and HSTS
Re: Proposal: Prefer secure origins for powerful new web platform features
Re: Verified Javascript for WebAppSec re-chartering?
Looking for a home for a proposed Credential Management API.
Fwd: Verified Javascript for WebAppSec re-chartering?
[webappsec] tomorrow's call CANCELLED
Subresource integrity in Chromium
[Integrity] Some comments on Cross-Origin leakage and content types
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
Proposal: not-a-scheme digest URI scheme, with graceful degradation
[webappsec] Re-chartering discussions at TPAC
Review request for a few WebAppSec specs.
[Integrity] Some comments on Subresource Integrity draft
[webappsec] Poll: new teleconference time
[MIX] Feedback on the private origin & self-signed certificate requirements
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
- RE: [MIX] Feedback on the private origin & self-signed certificate requirements
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
[CSP] compatibility between CSP1.1 and CSP2
Review request for a few WebAppSec specs.
HTML Imports vs unsafe-inline
[webappsec] Agenda: WebAppSec WG Teleconference 10-September-2014 08:00 PDT
CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
[CSP] why we do it!
Re: XMLHttpRequest. Support for "OPTIONS *" method.
- Re: XMLHttpRequest. Support for "OPTIONS *" method.
- Re: XMLHttpRequest. Support for "OPTIONS *" method.