mikewest / deprecating-document-domainLinks
`document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?
☆17Updated 2 years ago
Alternatives and similar repositories for deprecating-document-domain
Users that are interested in deprecating-document-domain are comparing it to the libraries listed below
Sorting:
- WebAppSec Content Security Policy☆221Updated 3 weeks ago
- Fetch Metadata☆75Updated 8 months ago
- A Modest Content Security Proposal☆40Updated 4 years ago
- Web Application Security Working Group repo☆647Updated 2 weeks ago
- Signature-based Resource Loading Restrictions☆43Updated 3 months ago
- ☆23Updated 3 years ago
- WebAppSec Subresource Integrity☆77Updated 4 months ago
- New proposals in the Privacy Community Group☆127Updated 3 years ago
- This is both a terrible and wonderful idea.☆12Updated 6 years ago
- Test cases and harnesses for URL testing☆30Updated 8 years ago
- A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.☆636Updated last month
- Agenda and minutes of meetings of the Privacy Community Group☆102Updated 2 months ago
- What is browser fingerprinting and how should specification authors address it.☆68Updated 2 months ago
- Opaque Response Blocking (CORB++)☆36Updated 3 years ago
- Cookies should take scheme into account, just like every other storage mechanism on the web.☆16Updated 5 years ago
- WebAppSec Secure Contexts☆37Updated 9 months ago
- ☆374Updated 9 months ago
- Network Error Logging☆89Updated 6 months ago
- A target privacy threat model for the Web☆24Updated 4 years ago
- ☆254Updated last week
- Parse Content Security Policy headers, warn about policy errors, safely manipulate, render, and optimise policies☆72Updated last week
- [On hold for now] A mechanism for origins to set their origin-wide configuration in a central location☆33Updated 3 years ago
- Security Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link …☆163Updated last week
- W3C specs and API reviews☆359Updated 2 weeks ago
- Guidelines, principles published on https://infosec.mozilla.org☆99Updated 4 months ago
- 🔒🔍 A Go package to scan sites against requirements for Chromium-maintained HSTS preload list.☆121Updated 5 months ago
- ☆25Updated 4 years ago
- Agenda/Minutes of Anti-Fraud Community Group meetings.☆20Updated this week
- Shavar/tracking protection lists used in prod☆149Updated 2 weeks ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆237Updated 2 months ago