Posts

Showing posts with the label Web Application Security Working Group

First Public Working Draft: A Well-Known URL for Changing Passwords

  The  Web Application Security Working Group  has published a First Public Working Draft of  A Well-Known URL for Changing Passwords . This specification defines a well-known URL that sites can use to make their change password forms discoverable by tools. This simple affordance provides a way for software to help the user find the way to change their password.

First Public Working Draft: Fetch Metadata Request Headers

27 June 2019 The  Web Application Security Working Group  has published a First Public Working Draft of  Fetch Metadata Request Headers . This document defines a set of Fetch metadata request headers that aim to provide servers with enough information to make a priori decisions about whether or not to service a request based on the way it was made, and the context in which it will be used.

W3C Invites Implementations of Content Security Policy Level 2

19 February 2015 The Web Application Security Working Group has published a Candidate Recommendation of Content Security Policy Level 2 . This specification updates Content Security Policy, fine-tuning the existing policy options, and introducing a number of new mechanisms that site authors can use to mitigate the risk of content injection and related attacks. Major differences from Content Security Policy Level 1 may be found in Section 1.1 of the document . With this publication, we move the earlier edition off the Recommendation Track to a Note ( Content Security Policy 1.0 ) and invite implementers to share their experience with CSP Level 2. Learn more about the Security Activity .

User Interface Safety Directives for Content Security Policy Draft Published

The Web Application Security Working Group has published the First Public Working Draft of User Interface Safety Directives for Content Security Policy . This document defines directives for the Content Security Policy mechanism to declare a set of input protections for a web resource's user interface, defines a non-normative set of heuristics for Web user agents to implement these input protections, and a reporting mechanism for when they are triggered. Learn more about the Security Activity .