mikewest / deprecating-document-domain
`document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?
☆16Updated last year
Alternatives and similar repositories for deprecating-document-domain:
Users that are interested in deprecating-document-domain are comparing it to the libraries listed below
- A proposal to partition :visited link history by top-level site and frame origin.☆19Updated 2 months ago
- A Modest Content Security Proposal☆40Updated 3 years ago
- Secure Contexts, but with _more_ secureness!☆20Updated 10 months ago
- Cookies should take scheme into account, just like every other storage mechanism on the web.☆16Updated 4 years ago
- ☆21Updated 2 years ago
- Opaque Response Blocking (CORB++)☆35Updated 2 years ago
- Fetch Metadata☆74Updated last month
- User Interface Security and the Visibility API☆11Updated 4 years ago
- Explainer and spec for the Content Indexing proposal☆29Updated 3 years ago
- Incrementally better cookies.☆22Updated 2 years ago
- `COEP: x-bikeshed-credentialless-unless-cors`☆28Updated 2 years ago
- Problem statement and basic mitigations for ephemeral fingerprinting on the web.☆21Updated 4 years ago
- Idiosyncracies of the HTML parser☆40Updated 5 months ago
- This is both a terrible and wonderful idea.☆11Updated 5 years ago
- Explainer for Schemeful Same-Site☆15Updated 4 years ago
- WebAppSec Secure Contexts☆34Updated last month
- [On hold for now] A mechanism for origins to set their origin-wide configuration in a central location☆33Updated 2 years ago
- Discussion area for security aspects of ECMAScript☆64Updated 7 years ago
- WebAppSec Subresource Integrity☆72Updated this week
- This is a tiny Chrome Extension that protects your from Clipboard XSS Attacks☆19Updated 9 years ago
- ☆38Updated 2 years ago
- A repository for the ServiceWorker static routing API.☆26Updated last month
- What is browser fingerprinting and how should specification authors address it.☆60Updated this week
- Quirks Mode Standard☆30Updated last month
- Test cases and harnesses for URL testing☆30Updated 8 years ago
- ☆59Updated last month
- Shorten (mangle) names in JavaScript code☆20Updated 6 years ago
- A proposal to standardize security semantics of cross-site cookies☆17Updated last year
- rewrite constructor arguments, call DOMPurify, profit☆67Updated 5 months ago
- Specification for the Client Hints infrastructure - privacy preserving proactive content negotiation☆63Updated 9 months ago