public-webappsec@w3.org from February 2016 by subject

[CSP] "sri" source expression to enforce SRI

[referrer] Should referrer policy change value of the Origin header?

[suborigins] Accessing workers from suborigins

[suborigins] Issues on GitHub

[UI Security] iframe URL indicator

[webappsec] Face to Face meeting survey

[webappsec] Teleconference Agenda 2016-Feb-10

CSP header protection

Embedded Enforcement and Cookie Controls

FYI: RFC7762 established a registry of CSP directives

HSTS priming vs preloading

In-browser sanitization first, "Safe Node" later?

Making it easier to deploy CSP.

new meta tags to protect code visibility or immuatbility

Proposal to add a browsing context named "_private"

Proposal: Marking HTTP As Non-Secure

Review of WebRTC 1.0 from Web Application Security Working Group

Teleconference Agenda 2016-Feb-24

Towards a minimum-viable credential management API.

Using client certificates for signing

Last message date: Monday, 29 February 2016 22:45:26 UTC