Web Application Security Working Group - Tools
- Mailing List
- member-webappsec
- public-webappsec
- Issue Tracking
- Issue Dashboard
- Other
- Minutes through ~2017
GitHub repositories
This list includes active GitHub repositories maintained by this group. To add a repository see the w3c.json documentation.
-
w3c/permissions
Permissions API
-
w3c/permissions-registry
Registry of known powerful features in the web platform.
-
w3c/webappsec
Web Application Security Working Group repo
-
w3c/webappsec-change-password-url
A Well-Known URL for Changing Passwords
-
w3c/webappsec-clear-site-data
WebAppSec Clear Site Data
-
w3c/webappsec-cors-for-developers
CORS for developers
-
w3c/webappsec-cowl
WebAppSec Confinement Origin Web Labels
-
w3c/webappsec-credential-management
WebAppSec Credential Management
-
w3c/webappsec-csp
WebAppSec Content Security Policy
-
w3c/webappsec-cspee
Content Security Policy: Embedded Enforcement
-
w3c/webappsec-fetch-metadata
Fetch Metadata
-
w3c/webappsec-mixed-content
WebAppSec Mixed Content
-
w3c/webappsec-permissions-policy
A mechanism to selectively enable and disable browser features and APIs
-
w3c/webappsec-post-spectre-webdev
Post-Spectre Web Development
-
w3c/webappsec-referrer-policy
WebAppSec Referrer Policy
-
w3c/webappsec-secure-contexts
WebAppSec Secure Contexts
-
w3c/webappsec-suborigins
Suborigins
-
w3c/webappsec-subresource-integrity
WebAppSec Subresource Integrity
-
w3c/webappsec-trusted-types
A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.
-
w3c/webappsec-uisecurity
User Interface Security and the Visibility API
-
w3c/webappsec-upgrade-insecure-requests
WebAppSec Upgrade Insecure Requests
-
w3c/webcrypto
The W3C Web Cryptography API