public-webappsec@w3.org from September 2015 by thread

`iframe[@sandbox]`: "sandblaster" JS library for analysis/modification James M. Greene (Wednesday, 30 September)

[CSP2]Is there a directive dealing with the window.opener.location phishing concern? Jerry Qu (Wednesday, 30 September)

Starting to create new repositories. Mike West (Wednesday, 30 September)

Fwd: Password generation classes Jonathan Kingston (Wednesday, 30 September)

Password generation classes Jonathan Kingston (Wednesday, 30 September)

SOP wiki was: A Somewhat Critical View of SOP (Same Origin Policy) Henry Story (Monday, 28 September)

[CSP2] connect-src 'self' and websockets André N. Klingsheim (Sunday, 27 September)

CSP3 as a polylithic set of modules? Mike West (Saturday, 26 September)

Permissions API Mike O'Neill (Saturday, 26 September)

CfC: Transition "Secure Contexts" to CR; deadline October 1st. Mike West (Thursday, 24 September)

SRI: data URIs and Blob URL Jerry Qu (Wednesday, 23 September)

[webappsec] Call for Consensus: COWL to FPWD Brad Hill (Monday, 21 September)

Re: HSTS, mixed content, and priming Jacob Hoffman-Andrews (Monday, 21 September)

RfC: Service Workers Arthur Barstow (Monday, 21 September)

WebAppSec Teleconference Agenda 21-Sep-2015 Daniel Veditz (Sunday, 20 September)

SRI: edge case when loading the same stylesheet twice in a document Francois Marier (Wednesday, 16 September)

Re: Testing W3C's HTTPS setup Mike West (Monday, 14 September)

[clear-site-data] clearing information about URLs visited Nick Doty (Monday, 14 September)

Secure Contexts: It's worth taking another look. Mike West (Friday, 11 September)

Call for Exclusions (Update): Entry Point Regulation Xueyuan Jia (Wednesday, 9 September)

Re: [mixed-content] DASH Players and Mixed Content Göran AP Eriksson (Tuesday, 8 September)

CfC: Republish MIX as a CR; deadline Sept. 15th. Mike West (Tuesday, 8 September)

Referrer value for resources fetched from CSS Yoav Weiss (Tuesday, 8 September)

Split the `w3c/webappsec` respository? Mike West (Tuesday, 8 September)

[CSP2] browser behavior on frame-ancestors violation through previous iframe content navigation fredericdelaporte@free.fr (Friday, 4 September)

Re: CSP 401 Issue Anne van Kesteren (Saturday, 5 September)

Caching of web content based on hashes? Christian Nygaard (Wednesday, 2 September)

Automatic private browsing upgrades Francois Marier (Thursday, 3 September)

[webappsec] Next teleconference, 7-Sep-2015, CANCELLED Brad Hill (Wednesday, 2 September)

[webappsec] CSP2 Implementation Report Brad Hill (Wednesday, 2 September)

Re: [CSP2] How to restrict resources linking to yao zhongxiao (Wednesday, 2 September)

[webappsec] more CSP test review begging Brad Hill (Tuesday, 1 September)

Re: Coming back to CREDENTIAL. Mike West (Tuesday, 1 September)

Re: A Somewhat Critical View of SOP (Same Origin Policy) Tony Arcieri (Tuesday, 1 September)

Last message date: Wednesday, 30 September 2015 21:23:12 UTC