Web Application Security Working Group - Tools
- Issue Tracking
- Issue Dashboard
- Mailing List
- member-webappsec Restricted archives
- public-webappsec
- Other
- Minutes through ~2017
GitHub repositories
- 
                    federated-credentials
- 
                    password-credentials
- 
                    
- 
                    permissions-registryRegistry of known powerful features in the web platform. 
- 
                    trusted-typesA browser API to prevent DOM-Based Cross Site Scripting in modern web applications. 
- 
                    
- 
                    webappsec-change-password-urlA Well-Known URL for Changing Passwords 
- 
                    
- 
                    
- 
                    
- 
                    
- 
                    
- 
                    
- 
                    webappsec-dbscDevice Bound Session Credentials: A Protocol for Protecting From Cookie Theft 
- 
                    
- 
                    
- 
                    webappsec-passkey-endpointsA well-known URL for passkey relying party endpoints 
- 
                    webappsec-permissions-policyA mechanism to selectively enable and disable browser features and APIs 
- 
                    
- 
                    
- 
                    
- 
                    webappsec-standardizing-security-semantics-of-cross-site-cookiesA WebAppSec note on standardizing the security semantics of cross-site cookies and proposes standardizing these semantics. w3c/webappsec-standardizing-security-semantics-of-cross-site-cookies 
- 
                    
- 
                    
- 
                    webappsec-uisecurityUser Interface Security and the Visibility API 
- 
                    webappsec-upgrade-insecure-requestsWebAppSec Upgrade Insecure Requests 
-