[REFERRER] Combining referrer policies
[webappsec] Tomorrow's teleconference CANCELLED
Accessing the same CORS-Resource from multiple sites
Fwd: Subresource Integrity (SRI) is now a W3C Recommendation
CORS restrictions on preflight (too) strict?
[suborigins] Understanding the syntax
[suborigins] Understanding the syntax
SameSite cookies and SAML
[webappsec] 6/15 call CANCELLED
SameSite=Strict cookies for a user entered URL
CSP script-src - Allow Js Events
Whitelisting external resources by hash (was Re: Finalizing the shape of CSP ‘unsafe-dynamic’)
- Re: Whitelisting external resources by hash (was Re: Finalizing the shape of CSP ‘unsafe-dynamic’)
- Re: Whitelisting external resources by hash (was Re: Finalizing the shape of CSP ‘unsafe-dynamic’)
Should permission requests require a user gesture?
Finalizing the shape of CSP ‘unsafe-dynamic’
- Re: Finalizing the shape of CSP ‘unsafe-dynamic’