mikewest / deprecating-document-domain
`document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?
☆16Updated last year
Alternatives and similar repositories for deprecating-document-domain:
Users that are interested in deprecating-document-domain are comparing it to the libraries listed below
- Opaque Response Blocking (CORB++)☆35Updated 2 years ago
- Secure Contexts, but with _more_ secureness!☆20Updated 8 months ago
- Problem statement and basic mitigations for ephemeral fingerprinting on the web.☆20Updated 4 years ago
- ☆21Updated 2 years ago
- Cookies should take scheme into account, just like every other storage mechanism on the web.☆16Updated 4 years ago
- User Interface Security and the Visibility API☆11Updated 3 years ago
- Incrementally better cookies.☆22Updated 2 years ago
- Idiosyncracies of the HTML parser☆38Updated 3 months ago
- ☆34Updated 4 years ago
- WebAppSec Secure Contexts☆33Updated last year
- `COEP: x-bikeshed-credentialless-unless-cors`☆28Updated 2 years ago
- WebAppSec Subresource Integrity☆71Updated 3 months ago
- Archive of DNT deliverables☆12Updated 3 years ago
- Explainer and spec for the Content Indexing proposal☆29Updated 3 years ago
- Fetch Metadata☆75Updated 8 months ago
- A proposal to partition :visited link history by top-level site and frame origin.☆14Updated this week
- Test Utils Standard☆17Updated 11 months ago
- Explainers from Mozilla contributors☆17Updated 2 weeks ago
- Quirks Mode Standard☆30Updated 2 months ago
- Discussion area for security aspects of ECMAScript☆64Updated 7 years ago
- a language acceptor for the JavaScript Pattern (regular expression internals) grammar☆15Updated 2 years ago
- Explainer for Schemeful Same-Site☆15Updated 4 years ago
- [On hold for now] A mechanism for origins to set their origin-wide configuration in a central location☆33Updated 2 years ago
- A zoo for malicious NPM packages☆20Updated 2 years ago
- Homebrew formulae for ECMAScript engines☆14Updated 7 years ago
- ☆38Updated 2 years ago
- What is browser fingerprinting and how should specification authors address it.☆57Updated last week
- Document describing the process for making changes to ECMA-262☆30Updated last month
- rewrite constructor arguments, call DOMPurify, profit☆67Updated 3 months ago