[REFERRER] Combining referrer policies
[review] Performance API's, Security and Privacy
[suborigins] Understanding the syntax
[UPGRADE] upgrade-insecure-request-with-fallback
[webappsec] 6/15 call CANCELLED
[webappsec] Tomorrow's teleconference CANCELLED
[webappsec] Tomorrow's teleconference CANCELLED.
Accessing the same CORS-Resource from multiple sites
CORS restrictions on preflight (too) strict?
CSP script-src - Allow Js Events
Draft minutes from 16,17-May-2016 F2F @Mozilla, Mtn View
Finalizing the shape of CSP ‘unsafe-dynamic’
- Mike West (Monday, 20 June)
- Devdatta Akhawe (Wednesday, 8 June)
- Artur Janc (Monday, 6 June)
- Mike West (Monday, 6 June)
- Devdatta Akhawe (Monday, 6 June)
- Mike West (Monday, 6 June)
- Devdatta Akhawe (Saturday, 4 June)
- Artur Janc (Friday, 3 June)
- Devdatta Akhawe (Friday, 3 June)
- Brad Hill (Friday, 3 June)
- Artur Janc (Friday, 3 June)
- Brad Hill (Friday, 3 June)
- Artur Janc (Thursday, 2 June)
Fwd: Subresource Integrity (SRI) is now a W3C Recommendation
SameSite cookies and SAML
SameSite=Strict cookies for a user entered URL
Should permission requests require a user gesture?
upgrade-insecure-request-with-fallback
VC meeting to discuss Permissions spec
Whitelisting external resources by hash (was Re: Finalizing the shape of CSP ‘unsafe-dynamic’)
- Artur Janc (Wednesday, 8 June)
- Devdatta Akhawe (Wednesday, 8 June)
- Daniel Veditz (Wednesday, 8 June)
- Artur Janc (Wednesday, 8 June)
- Artur Janc (Wednesday, 8 June)
- Harssh Mahajan (Wednesday, 8 June)
- Artur Janc (Wednesday, 8 June)
- Brad Hill (Tuesday, 7 June)
- Mike West (Tuesday, 7 June)
- Artur Janc (Tuesday, 7 June)
- Brad Hill (Tuesday, 7 June)
- Mike West (Tuesday, 7 June)
Last message date: Thursday, 30 June 2016 23:16:49 UTC