Issues
- 10
Could someone explain the actual tangible security implication of a browser without CORB and ORB?
#44 opened by markg85 - 12
HLS manifest is fetched across origins
#29 opened by annevk - 3
Blocking JSON breaks web compat
#43 opened by farre - 3
- 2
Avoid ORB checks for navigator.sendBeacon
#41 opened by zcorpan - 1
ORB uses `audio-or-video-type-pattern-matching-algorithm` in an indeterministic way.
#40 opened by farre - 8
- 1
Clarify the behaviour of Javascript Validation when we are waiting for the full body
#38 opened by sefeng211 - 47
Graceful fallback for future image types
#3 opened by anforowicz - 3
It is unclear when "To determine whether to allow response response to a request request, run these steps" runs.
#35 opened by smaug---- - 1
Authentication Request and 401 response code
#37 opened by sefeng211 - 6
How to decode potential JavaScript
#7 opened by annevk - 5
- 7
embed/object
#5 opened by annevk - 8
Consider an alternative strategy for media that does not rely on media elements directly
#33 opened by anforowicz - 6
Should ORB block application/javascript with either JSON or JS-parser-breakers
#30 opened by anforowicz - 10
No size limit
#22 opened by MattMenke2 - 0
Stricter filter for responses without MIME type
#28 opened by annevk - 0
Blocklist based on sniffing
#27 opened by annevk - 1
- 4
- 4
- 1
JSON vs Javascript lists
#2 opened by anforowicz - 3
Limit performance impact by restricting Javascript sniffing/parsing to "script" destinations
#25 opened by anforowicz - 2
Impact on streaming responses
#24 opened by anforowicz - 0
Restrict fetch(..., { mode: "no-cors" }) more
#18 opened by annevk - 0
- 1
- 2
- 1
- 0
- 0