[CSP] compatibility between CSP1.1 and CSP2
[CSP] Compatibility with 1.1 or 1.0
[CSP] kill or delay child-src?
[CSP] may we have script-ancestors to protect JSONP call
[CSP] Regarding style-src unsafe-eval and CSSOM
[CSP] why we do it!
[Integrity] hash in HTTP header field
[Integrity] Some comments on Cross-Origin leakage and content types
- Devdatta Akhawe (Thursday, 25 September)
- Ángel González (Thursday, 25 September)
- Ilya Grigorik (Tuesday, 23 September)
- Devdatta Akhawe (Tuesday, 23 September)
- Brad Hill (Tuesday, 23 September)
- Arjan Veenstra (Monday, 22 September)
- Arjan Veenstra (Monday, 22 September)
- Devdatta Akhawe (Monday, 22 September)
- Anne van Kesteren (Sunday, 21 September)
- Arjan Veenstra (Saturday, 20 September)
[Integrity] Some comments on Subresource Integrity draft
[MIX] Feedback on the private origin & self-signed certificate requirements
- Devdatta Akhawe (Wednesday, 17 September)
- Brad Hill (Wednesday, 17 September)
- Chen, Zhigao (Wednesday, 17 September)
- Hill, Brad (Tuesday, 16 September)
- Mike West (Tuesday, 16 September)
- Hill, Brad (Monday, 15 September)
- Chen, Zhigao (Sunday, 14 September)
- Chen, Zhigao (Monday, 15 September)
- Mike West (Sunday, 14 September)
[webappsec] Agenda: WebAppSec WG Teleconference 10-September-2014 08:00 PDT
[webappsec] Changing my organizational hats
[webappsec] Concluding the Last Call period for CSP Level 2
[webappsec] Poll: new teleconference time
[webappsec] Re-chartering discussions at TPAC
[webappsec] tomorrow's call CANCELLED
CfC: Publish a new WD of MIX.
CSP for WebRTC
CSP Level 2 last call comment
CSP reports on eval() and inline
- Neil Matatall (Tuesday, 16 September)
- Pete Freitag (Friday, 5 September)
- Pawel Krawczyk (Thursday, 4 September)
- Neil Matatall (Thursday, 4 September)
- Hill, Brad (Thursday, 4 September)
- Neil Matatall (Thursday, 4 September)
- Neil Matatall (Thursday, 4 September)
- Hill, Brad (Thursday, 4 September)
- Mike West (Thursday, 4 September)
- Pawel Krawczyk (Wednesday, 3 September)
CSP: Minimum cipher strength
- Hill, Brad (Monday, 15 September)
- Austin William Wright (Monday, 15 September)
- Anne van Kesteren (Monday, 15 September)
- Jim Manico (Sunday, 14 September)
- Tom Ritter (Sunday, 14 September)
- Ryan Sleevi (Wednesday, 10 September)
- Daniel Kahn Gillmor (Wednesday, 10 September)
- Frederik Braun (Wednesday, 10 September)
- Mike West (Wednesday, 10 September)
- Frederik Braun (Tuesday, 9 September)
- John Yeuk Hon Wong (Tuesday, 9 September)
- Ángel González (Monday, 8 September)
- Jeffrey Walton (Monday, 8 September)
- Erlend Oftedal (Monday, 8 September)
Defining secure-enough origins.
Feature-detecting a Content Security Policy
Fwd: Verified Javascript for WebAppSec re-chartering?
HTML Imports vs unsafe-inline
ISSUE-65: Does "no referrer" specify a state or is it a token? is a token with a space problematic?
Looking for a home for a proposed Credential Management API.
Proposal: not-a-scheme digest URI scheme, with graceful degradation
Proposal: Prefer secure origins for powerful new web platform features
Redirects and HSTS
- Daniel Kahn Gillmor (Monday, 29 September)
- Anne van Kesteren (Saturday, 27 September)
- Anne van Kesteren (Saturday, 27 September)
- Anne van Kesteren (Saturday, 27 September)
- Ryan Sleevi (Saturday, 27 September)
- Anne van Kesteren (Saturday, 27 September)
- Daniel Veditz (Saturday, 27 September)
- =JeffH (Friday, 26 September)
- Ryan Sleevi (Friday, 26 September)
- Anne van Kesteren (Friday, 26 September)
- Anne van Kesteren (Friday, 26 September)
- =JeffH (Friday, 26 September)
- Tanvi Vyas (Friday, 26 September)
- Tanvi Vyas (Friday, 26 September)
- Ryan Sleevi (Friday, 26 September)
- Anne van Kesteren (Friday, 26 September)
- Chris Palmer (Friday, 26 September)
- Tanvi Vyas (Friday, 26 September)
- Mike West (Friday, 26 September)
- Anne van Kesteren (Friday, 26 September)
- Mike West (Friday, 26 September)
- Anne van Kesteren (Friday, 26 September)
- Mike West (Friday, 26 September)
- Anne van Kesteren (Friday, 26 September)
Review request for a few WebAppSec specs.
SRI: <a> vs integrity
Subresource integrity in Chromium
Verified Javascript for WebAppSec re-chartering?
webappsec-ISSUE-67: WebRTC via 'connect-src'?
XMLHttpRequest. Support for "OPTIONS *" method.
Last message date: Monday, 29 September 2014 14:01:40 UTC