WICG/origin-policy
[On hold for now] A mechanism for origins to set their origin-wide configuration in a central location
NOASSERTION
Pinned issues
Issues
- 2
Work on origin policy is on hold for now
#104 opened - 1
Nonces in Origin-CSPs
#101 opened - 0
- 0
- 1
- 6
Enabling fast Origin Policy application
#96 opened - 0
- 0
Test plan tracking issue
#92 opened - 0
Allowing A/B testing of origin policies
#89 opened - 0
Compare header parsing error/empty cases
#88 opened - 12
Strictness in header parsing
#87 opened - 4
- 9
- 3
- 4
- 2
Parameters on Structured Headers
#78 opened - 1
- 0
- 1
Feature Policy stability
#74 opened - 7
- 3
Cross-Origin-Resource-Policy defaulting
#95 opened - 0
- 10
- 4
- 1
- 1
support document policies
#64 opened - 1
Define report-to
#62 opened - 3
Consolidating allowed/preferred?
#61 opened - 3
- 18
- 10
- 4
Error handling discussion
#49 opened - 5
- 1
- 1
- 16
- 2
"version" is a confusing term
#43 opened - 1
"Suffix" in 2.3.1. is not defined
#42 opened - 1
- 1
Consider different OP announcement value
#40 opened - 6
Multiple Sec-Origin-Policy headers
#36 opened - 4
Multi-definition of configurations
#35 opened - 4
CSP without policy attribute
#34 opened - 0
MIME type naming
#33 opened - 8
JSON parsing not defined
#32 opened - 2
Interaction with suborigins
#31 opened - 0
TODO if implemented by two browsers
#30 opened - 2
Origin Policy manifest fetching and HTTP
#28 opened - 4
Fetch manifests on redirects
#27 opened - 4
Should HSTS be part of this
#25 opened