20:56:07 RRSAgent has joined #webappsec 20:56:07 logging to http://www.w3.org/2012/05/08-webappsec-irc 20:56:22 puhley has joined #webappsec 20:56:28 jeffh has joined #webappsec 20:58:04 zakim, this will be 92794 20:58:04 ok, bhill2; I see SEC_WASWG()5:00PM scheduled to start in 2 minutes 20:58:28 Meeting: WebAppSec Teleconference, May 8, 2012 20:58:34 Chair: bhill2, ekr 20:59:10 Scribe: Peleus Uhley 20:59:14 Agenda: http://lists.w3.org/Archives/Public/public-webappsec/2012May/0047.html 20:59:22 ScribeNick: puhley 20:59:55 rrsagent, begin 21:00:17 abarth has joined #webappsec 21:00:48 Zakim, who is on the phone 21:00:48 I don't understand 'who is on the phone', abarth 21:01:15 zakim, who is here 21:01:15 bhill2, you need to end that query with '?' 21:01:20 zakim, who is here? 21:01:20 SEC_WASWG()5:00PM has not yet started, bhill2 21:01:21 On IRC I see abarth, jeffh, puhley, RRSAgent, Zakim, bhill2, dhuang3, tanvi, gioma1, dveditz, odinho, anne, timeless, mkwst, trackbot, bhill22, caribou 21:01:34 Zakim, who is on the phone? 21:01:34 SEC_WASWG()5:00PM has not yet started, abarth 21:01:36 On IRC I see abarth, jeffh, puhley, RRSAgent, Zakim, bhill2, dhuang3, tanvi, gioma1, dveditz, odinho, anne, timeless, mkwst, trackbot, bhill22, caribou 21:02:07 cory has joined #webappsec 21:02:12 zakim, who is speaking? 21:02:12 sorry, bhill2, I don't know what conference this is 21:02:18 zakim, this is 92794 21:02:18 ok, bhill2; that matches SEC_WASWG()5:00PM 21:02:24 zakim, who is on the phone? 21:02:24 On the phone I see +1.650.678.aaaa, +1.866.317.aabb, +1.415.832.aacc, abarth, ??P5, +1.650.386.aadd, +1.360.793.aaee, +1.425.865.aaff, +1.408.320.aagg 21:02:34 -??P5 21:02:34 zakim aadd is bhill2 21:02:40 zakim, aadd is bhill2 21:02:40 +bhill2; got it 21:02:48 zakim, who is speaking? 21:02:53 it remembered my phone number! amazing 21:02:59 bhill2, listening for 10 seconds I heard sound from the following: +1.650.678.aaaa (15%), +1.415.832.aacc (26%), bhill2 (4%) 21:02:59 zakim, aagg is dhuang3 21:03:01 +dhuang3; got it 21:03:04 i'm aadd 21:03:06 +??P5 21:03:09 zakim aacc is puhley 21:03:29 zakim, aacc is puhley 21:03:29 +puhley; got it 21:03:32 zakim, ??P5 is gioma1 21:03:32 +gioma1; got it 21:04:04 s/zakim aacc is puhley// 21:04:06 zakim, aaee is bhill2 21:04:06 +bhill2; got it 21:04:10 RRSAgent, draft minutes 21:04:10 I have made the request to generate http://www.w3.org/2012/05/08-webappsec-minutes.html timeless 21:04:13 zakim, aadd is tanvi 21:04:13 sorry, tanvi, I do not recognize a party named 'aadd' 21:04:26 Zakim, who is on the call? 21:04:26 On the phone I see +1.650.678.aaaa, +1.866.317.aabb, puhley, abarth, bhill2, bhill2.a, +1.425.865.aaff, dhuang3, gioma1 21:04:30 zakim, aagg is jeFFh 21:04:30 sorry, jeffh, I do not recognize a party named 'aagg' 21:04:40 zakim, mute puhley 21:04:40 puhley should now be muted 21:05:11 zakim, unmute puhley 21:05:11 puhley should no longer be muted 21:06:13 +[Microsoft] 21:06:37 bhill: I haven't posted day 2 minutes yet 21:07:03 ACTION: bhill to add day 2 minutes 21:07:03 Sorry, couldn't find user - bhill 21:07:37 jrossi has joined #webappsec 21:07:41 ACTION: bhill2 to add day 2 minutes from face to face meeting 21:07:42 Created ACTION-64 - Add day 2 minutes from face to face meeting [on Brad Hill - due 2012-05-15]. 21:09:01 agenda substitution: discuss more granular origin handling behavior in 1.0 in place of content type matching in 1.1 21:11:04 +dveditz 21:15:33 jrossi: Should sandbox directive be included in CSP 1.0? 21:15:47 abarth: There is an implementation in WebKit 21:16:39 bhill2: It was considered for 1.1 because it did not change the header or the syntax for CSP. Therefore, it could be supported in browsers without being in the 1.0 spec. 21:18:16 jrossi: Microsoft would like to get it into 1.0 so that they could officially validate their implementation. 21:19:15 jrossi: It meets the criteria for W3C requirements of two implementations. 21:23:06 issue-35? 21:23:06 ISSUE-35 does not exist 21:23:15 s/issue-35?// 21:23:18 s/ISSUE-35 does not exist// 21:27:46 issue-8? 21:27:46 ISSUE-8 -- Identify proper behavior for html added via plubins / object tag -- closed 21:27:46 http://www.w3.org/2011/webappsec/track/issues/8 21:27:53 s/issue-8?// 21:27:59 s|ISSUE-8 -- Identify proper behavior for html added via plubins / object tag -- closed|| 21:28:04 s|http://www.w3.org/2011/webappsec/track/issues/8|| 21:28:13 RRSAgent, draft minutes 21:28:13 I have made the request to generate http://www.w3.org/2012/05/08-webappsec-minutes.html timeless 21:28:39 bhill2: This may cause confusion with regards to declaring CSP support if individual sub-features are not supported. For instance, if IE supports sandbox but does not support all of the directives and Firefox supports all of the directives but not the sandbox implementation. 21:29:16 ACTION: bhill2 to put question out to the list. 21:29:17 Created ACTION-65 - Put question out to the list. [on Brad Hill - due 2012-05-15]. 21:29:23 rrsagent set logs public-visible 21:29:33 rrsagent, set logs public-visible 21:29:42 s|rrsagent set logs public-visible|| 21:29:45 RRSAgent, draft minutes 21:29:45 I have made the request to generate http://www.w3.org/2012/05/08-webappsec-minutes.html timeless 21:31:10 abarth: When receiving multiple policies, the browser should combine them. 21:34:05 abarth: For experimental headers, the browser vendors implementing the experimental header will determine what works best for combining the header. 21:34:52 tanvi: Should there be same-origin restrictions for report-uri headers? 21:35:32 abarth: We will not allow report-uri in meta tag but we won't restrict it for headers. 21:38:28 bhill2: Should we allow more granular origins than just the domain? 21:39:54 dveditz: It would be good to define this in 1.0 so that expectations are set correctly going forward. 21:43:53 ACTION: abarth to add error handling behavior in 1.0 spec 21:43:53 Created ACTION-66 - Add error handling behavior in 1.0 spec [on Adam Barth - due 2012-05-15]. 21:46:54 lots oF noise on some line 21:47:24 I am on mute right now so it isn't me. 21:47:50 someone who is typing 21:47:59 neither me. Someone typing 21:50:14 ACTION: abarth to add a description for how to handle content-type in CSP 1.1 - 06/30/2012 21:50:14 Created ACTION-67 - Add a description for how to handle content-type in CSP 1.1 - 06/30/2012 [on Adam Barth - due 2012-05-15]. 21:52:33 bhill2: For clickjacking, we would pursue something similar to ClearClick. Giorgio is nominated as editor. 21:52:43 dhuang3 volunteers to be an additional editor. 21:57:25 ACTION: dhuang3 to coordinate with Giorgi on a draft proposal - 07/2012 21:57:25 Created ACTION-68 - Coordinate with Giorgi on a draft proposal - 07/2012 [on David Huang - due 2012-05-15]. 21:57:42 - +1.866.317.aabb 21:57:47 -[Microsoft] 21:57:48 - +1.650.678.aaaa 21:57:48 -dveditz 21:57:50 - +1.425.865.aaff 21:57:50 -abarth 21:57:51 -dhuang3 21:57:51 -gioma1 21:57:52 -bhill2.a 21:57:54 -puhley 21:57:56 -bhill2 21:57:57 SEC_WASWG()5:00PM has ended 21:57:59 Attendees were +1.650.678.aaaa, +1.866.317.aabb, +1.415.832.aacc, abarth, +1.650.386.aadd, +1.360.793.aaee, +1.425.865.aaff, +1.408.320.aagg, bhill2, dhuang3, puhley, gioma1, 21:58:03 ... [Microsoft], dveditz 21:58:22 RRSAgenet, make minutes 21:58:31 RRSAgent, make minutes 21:58:31 I have made the request to generate http://www.w3.org/2012/05/08-webappsec-minutes.html puhley 21:59:49 thank you, Josh 22:00:38 s/thank you, Josh// 22:01:00 trackbot, end meeting 22:01:00 Zakim, list attendees 22:01:00 sorry, trackbot, I don't know what conference this is 22:01:00 quit 22:01:08 RRSAgent, please draft minutes 22:01:08 I have made the request to generate http://www.w3.org/2012/05/08-webappsec-minutes.html trackbot 22:01:09 s/quit// 22:01:09 RRSAgent, bye 22:01:09 I see 6 open action items saved in http://www.w3.org/2012/05/08-webappsec-actions.rdf : 22:01:09 ACTION: bhill to add day 2 minutes [1] 22:01:09 recorded in http://www.w3.org/2012/05/08-webappsec-irc#T21-07-03 22:01:09 ACTION: bhill2 to add day 2 minutes from face to face meeting [2] 22:01:09 recorded in http://www.w3.org/2012/05/08-webappsec-irc#T21-07-41 22:01:09 ACTION: bhill2 to put question out to the list. [3] 22:01:09 recorded in http://www.w3.org/2012/05/08-webappsec-irc#T21-29-16 22:01:09 ACTION: abarth to add error handling behavior in 1.0 spec [4] 22:01:09 recorded in http://www.w3.org/2012/05/08-webappsec-irc#T21-43-53 22:01:09 ACTION: abarth to add a description for how to handle content-type in CSP 1.1 - 06/30/2012 [5] 22:01:09 recorded in http://www.w3.org/2012/05/08-webappsec-irc#T21-50-14 22:01:09 ACTION: dhuang3 to coordinate with Giorgi on a draft proposal - 07/2012 [6] 22:01:09 recorded in http://www.w3.org/2012/05/08-webappsec-irc#T21-57-25 22:01:16 RRSAgent, draft minutes 22:01:16 I have made the request to generate http://www.w3.org/2012/05/08-webappsec-minutes.html timeless