Pinned Repositories
cookie-incrementalism
Incrementally better cookies.
cookies-over-http-bad
Archived proposal from 2018. Perhaps the approach in mikewest/scheming-cookies will be more successful!
credentialmanagement
Credential Management
http-state-tokens
Incrementally better HTTP state management.
jslint-utils
Wrapper scripts for running JSLint locally, and for generating test reports for Hudson
nginx-static-etags
Nginx doesn't generate etags for static content. I'd like it to. Let's see if I can remember some C from college.
privacy-budget
securer-contexts
Secure Contexts, but with _more_ secureness!
tc39-proposal-literals
Literals could be different than non-literals.
vimroom
Simulating a vaguely WriteRoom-like environment in Vim.
mikewest's Repositories
mikewest/http-state-tokens
Incrementally better HTTP state management.
mikewest/privacy-budget
mikewest/securer-contexts
Secure Contexts, but with _more_ secureness!
mikewest/baseline-header
What if developers could opt-into better default behaviors en masse, forcing them to pick and choose the legacy risks they want to enable.
mikewest/deprecating-document-domain
`document.domain` intentionally weakens the only security boundary we have. Perhaps we can dump it?
mikewest/homedir
Public home directory files
mikewest/sanitizer-playground
A demonstration of the HTML Sanitizer API.
mikewest/deprecate-it
Deprecate it.
mikewest/mitigation-supply
Mitigations. Supplied.
mikewest/mikewest.org
mikewest/privacy-policy-discovery
Policy documents should be discoverable.
mikewest/injection-mitigated
`[InjectionMitigated]` WebIDL Attribute
mikewest/origin-api
An `Origin` object might be nice to have.
mikewest/placid
A manifest v3 (and modified) version of Palmerized Chrome.
mikewest/purposeful-permissions
mikewest/a-priori-resource-assertions
Wouldn't it be nice if we could know things about a server's response _before_ we receive it?
mikewest/anti-exfil
mikewest/incentivize-origin-checks
Perhaps we can help developers prioritize origin checks in `MessageEvent` handlers.
mikewest/inline-integrity
Inline integrity.
mikewest/pepc-install
An `<install>` element might be nice.
mikewest/progress
A progress bar. Nothing interesting.
mikewest/scratchpad
mikewest/content
The content behind MDN Web Docs
mikewest/draft-pardue-http-identity-digest
A field to send the unencoded digest of HTTP things
mikewest/html
HTML Standard
mikewest/observable
Observable API proposal
mikewest/rfc9421-sri-profile
A profile of HTTP Message Signatures appropriate for integrity/provenance validation.
mikewest/sha2-it
mikewest/summernote
Super simple WYSIWYG editor
mikewest/webappsec-dbsc
Device Bound Session Credentials: A Protocol for Protecting From Cookie Theft