mikewest / deprecating-document-domain
`document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?
☆16Updated last year
Related projects ⓘ
Alternatives and complementary repositories for deprecating-document-domain
- Opaque Response Blocking (CORB++)☆35Updated 2 years ago
- Problem statement and basic mitigations for ephemeral fingerprinting on the web.☆20Updated 3 years ago
- Secure Contexts, but with _more_ secureness!☆19Updated 6 months ago
- A Modest Content Security Proposal☆39Updated 3 years ago
- A proposal to partition :visited link history by top-level site and frame origin.☆13Updated this week
- ☆20Updated 2 years ago
- User Interface Security and the Visibility API☆11Updated 3 years ago
- Cookies should take scheme into account, just like every other storage mechanism on the web.☆16Updated 4 years ago
- `COEP: x-bikeshed-credentialless-unless-cors`☆28Updated 2 years ago
- Incrementally better cookies.☆22Updated 2 years ago
- Quirks Mode Standard☆29Updated this week
- ☆38Updated 2 years ago
- Explainer and spec for the Content Indexing proposal☆29Updated 3 years ago
- Fetch Metadata☆75Updated 6 months ago
- Discussion area for security aspects of ECMAScript☆64Updated 6 years ago
- [On hold for now] A mechanism for origins to set their origin-wide configuration in a central location☆33Updated 2 years ago
- Archive of DNT deliverables☆12Updated 3 years ago
- WebAppSec Confinement Origin Web Labels☆11Updated 3 years ago
- Keyboard Lock☆20Updated last year
- WebAppSec Subresource Integrity☆70Updated last month
- Homebrew formulae for ECMAScript engines☆14Updated 6 years ago
- TC39 proposal for mitigating prototype pollution☆43Updated last year
- Spec defining browser support for file/directory upload by drag-and-drop☆41Updated 3 months ago
- Test Utils Standard☆17Updated 9 months ago
- Explainers from Mozilla contributors☆17Updated last month
- Explainer for Schemeful Same-Site☆15Updated 4 years ago
- Adding an optional operand to the DebuggerStatement production of JS☆13Updated 6 years ago
- What is browser fingerprinting and how should specification authors address it.☆56Updated this week
- A repository for the ServiceWorker static routing API.☆26Updated 3 weeks ago
- This is a tiny Chrome Extension that protects your from Clipboard XSS Attacks☆19Updated 9 years ago