Sign in

Open Web Docs

@openwebdocs.front-end.social.ap.brid.gy
19 followers 0 following 37 posts

Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. [bridged from front-end.social/@openwebdocs on the fediverse by fed.brid.gy ]

PostsRepliesMedia
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 22/09/2026
Microsoft Edge sponsors Open Web Docs for the 7th consecutive year. Continued support enables us to create and maintain web platform documentation and browser compatibility data. Thank you, Microsoft Edge! openwebdocs.org/content/posts/micro…
openwebdocs.org
Thank you, Microsoft Edge!
Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. We are a community of web developers, standards makers, and technology companies that rely on this documentation as critical digital infrastructure, and we work cooperatively to ensure its long-term success and maintenance.
011
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 23/06/2026
We've completed our work on Web Security documentation on @mdn ! The entire MDN content tree has been reworked and now features in-depth information on: - Attacks - Defenses - Authentication - Threat Modeling ↪️ Blog post openwebdocs.org/content/posts/secur…
openwebdocs.org
Web Security docs on MDN
Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. We are a community of web developers, standards makers, and technology companies that rely on this documentation as critical digital infrastructure, and we work cooperatively to ensure its long-term success and maintenance.
1616
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 23/06/2026
We've completed our work on Web Security documentation on @mdn ! The entire MDN content tree has been reworked and now features in-depth information on: - Attacks - Defenses - Authentication - Threat Modeling ↪️ Blog post openwebdocs.org/content/posts/secur…
openwebdocs.org
Web Security docs on MDN
Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. We are a community of web developers, standards makers, and technology companies that rely on this documentation as critical digital infrastructure, and we work cooperatively to ensure its long-term success and maintenance.
1616
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 20/04/2026
We've updated MDN's guide on Subresource Integrity (SRI) and added docs for the HTML `integrity` attribute. The SRI docs now talk about the fact that you can provide multiple `integrity` values (using the same or different hash functions) and how browsers will handle that. Thanks to @codingjoe […]
front-end.social
Original post on front-end.social
001
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 14/04/2026
We've written new MDN security docs on Threat Modeling and provided an example threat model for a (simplified) blog website. Threat modeling is a form of risk assessment in which you create a representation of a system so you can identify relevant security and privacy concerns, understand what […]
front-end.social
Original post on front-end.social
004
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 01/04/2026
We've written a new guide on Fetch Metadata! Fetch metadata is a group of HTTP request headers. They tell you if requests are navigation between documents, request for a subresource, or requests made from JavaScript, and whether they are same-origin, or same-site, or from completely different […]
front-end.social
Original post on front-end.social
001
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 16/03/2026
RE: front-end.social/@floscholz/1162398… Catch Daniel and Florian at @FOSSBackstage today and tomorrow!
front-end.social
002
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 26/02/2026
We've written a new guide on Session Management! Once you authenticated your users, you will need to manage their sessions. This guide walks you through two different architectures for session management (cookies and JWTs) and describes common session attacks to watch out for. For now, this […]
front-end.social
Original post on front-end.social
104
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 26/02/2026
We've written a new guide on Session Management! Once you authenticated your users, you will need to manage their sessions. This guide walks you through two different architectures for session management (cookies and JWTs) and describes common session attacks to watch out for. For now, this […]
front-end.social
Original post on front-end.social
104
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 12/02/2026
Hey @niklasmerz, thank you so much for your kind donation to Open Web Docs! 💜 It's always a pleasure talking to you about WebViews and figuring out compat data for caniwebview.com Everyone, join the W3C WebView CG to be part of WebView conversations: www.w3.org/groups/cg/webview
caniwebview.com
Can I WebView…
Documentation for WebView capatibilities, limitations and features
003
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 10/02/2026
Open Web Docs 2025 Report We're reflecting on our fifth year of ensuring the long-term health of web platform documentation. Happy 5-year anniversary to us! 🍰 Thanks to the many individuals and organizations for your support on our journey! 💜 openwebdocs.org/content/reports/2025
openwebdocs.org
Open Web Docs Impact and Transparency Report 2025
Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. We are a community of web developers, standards makers, and technology companies that rely on this documentation as critical digital infrastructure, and we work cooperatively to ensure its long-term success and maintenance.
004
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 04/02/2026
Do you delegate web security to security specialists or are you responsible yourself for implementing web security features and practices? The W3C SWAG CG survey asks this and other questions and we would value your input as we create Web Security documentation […]
front-end.social
Original post on front-end.social
005
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 29/01/2026
We've written a new guide on Passkeys! Passkeys address many of the most serious weaknesses of other authentication methods. In this guide we will: - Introduce you to the WebAuthn API - Go through registration and sign-in flows - Give an overview of the security properties of passkeys - […]
front-end.social
Original post on front-end.social
017
Reposted by Open Web Docs
Daniel Appelquist @torgo.mastodon.social.ap.brid.gy · 31/01/2026
Learning about WebViews at the #FOSDEM Browsers & Web Platform dev room, including the caniwebview.com site that (much like CanIUse) tells developers which features are available in which webviews – using BCD data maintained by OpenWebDocs (which was presented earlier by @patrickbrosset).
caniwebview.com
Can I WebView…
Documentation for WebView capatibilities, limitations and features
010
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 29/01/2026
We've written a new guide on Passkeys! Passkeys address many of the most serious weaknesses of other authentication methods. In this guide we will: - Introduce you to the WebAuthn API - Go through registration and sign-in flows - Give an overview of the security properties of passkeys - […]
front-end.social
Original post on front-end.social
017
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 10/12/2025
RE: mas.to/@patrickbrosset/115695467325… In 2025, we systematically collected compat data for 28 browser releases: Firefox 135 - 147 Chrome 133 - 144 Safari 18.4, 26, 26.2 We're keeping your compat tables up-to-date.
mas.to
001
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 05/12/2025
React2Shell reflects a prototype pollution bug. We recently wrote about how defend against prototype pollution attacks: developer.mozilla.org/en-US/docs/We…
developer.mozilla.org
JavaScript prototype pollution - Security | MDN
Prototype pollution is a vulnerability where an attacker can add or modify properties on an object's prototype. This means malicious values can unexpectedly appear on objects in your application, often leading to logic errors or additional attacks like cross-site scripting (XSS).
000
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 01/12/2025
We've written a new guide on one-time password (OTP) authentication. The article discusses three common implementations for one-time passwords: E-mail, SMS, and time-based one-time passwords (TOTP). We recommend TOTP in this comparison. Learn why […]
front-end.social
Original post on front-end.social
003
Reposted by Open Web Docs
Daniel Appelquist @torgo.mastodon.social.ap.brid.gy · 13/11/2025
Hanging out with the awesome, hand chiseled, @openwebdocs crew @estelle, @floscholz and Will Bamberg at @w3c #TPAC in Kobe!
000
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 04/11/2025
We're creating a new series of articles about Authentication. Our first new guide is about classic passwords -- the original method to authenticate and still the most common on the web. A refresher about password attacks, defenses and best practices […]
front-end.social
Original post on front-end.social
001
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 20/10/2025
We've written a new guide on JavaScript Prototype Pollution and how to defend against it: developer.mozilla.org/en-US/docs/We… Many thanks to @joshcena, Aaron Shim, and Maurice Dauer for your help and feedback.
developer.mozilla.org
JavaScript prototype pollution - Security | MDN
Prototype pollution is a vulnerability where an attacker can add or modify properties on an object's prototype. This means malicious values can unexpectedly appear on objects in your application, often leading to logic errors or additional attacks like cross-site scripting (XSS).
004
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 20/10/2025
We've written a new guide on JavaScript Prototype Pollution and how to defend against it: developer.mozilla.org/en-US/docs/We… Many thanks to @joshcena, Aaron Shim, and Maurice Dauer for your help and feedback.
developer.mozilla.org
JavaScript prototype pollution - Security | MDN
Prototype pollution is a vulnerability where an attacker can add or modify properties on an object's prototype. This means malicious values can unexpectedly appear on objects in your application, often leading to logic errors or additional attacks like cross-site scripting (XSS).
004
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 14/10/2025
We've written a new guide on Supply Chain Attacks: developer.mozilla.org/en-US/docs/We… Many thanks to the W3C SWAG CG and @ljharb for the reviews and feedback! #websecurity
developer.mozilla.org
Supply chain attacks - Security | MDN
A software supply chain consists of all the software and tools used to create and maintain a software product. This includes not only the software developed for the product itself but all the software and tools used in its production.
005
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 14/10/2025
We've written a new guide on Supply Chain Attacks: developer.mozilla.org/en-US/docs/We… Many thanks to the W3C SWAG CG and @ljharb for the reviews and feedback! #websecurity
developer.mozilla.org
Supply chain attacks - Security | MDN
A software supply chain consists of all the software and tools used to create and maintain a software product. This includes not only the software developed for the product itself but all the software and tools used in its production.
005
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 30/09/2025
We're happy to share that @sovtechfund invests in Web Security and Privacy Documentation! Over the coming year, Open Web Docs will be working on creating and updating Security and Privacy documentation for web developers on @mdn. Full announcement […]
front-end.social
Original post on front-end.social
075
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 30/09/2025
We're happy to share that @sovtechfund invests in Web Security and Privacy Documentation! Over the coming year, Open Web Docs will be working on creating and updating Security and Privacy documentation for web developers on @mdn. Full announcement […]
front-end.social
Original post on front-end.social
075
Reposted by Open Web Docs
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 14/05/2025
We've written a new guide on XS-Leaks: developer.mozilla.org/en-US/docs/We… Many thanks to @freddy, Hamish Willee, @MartinaKraus11, and @terjanq for your reviews and collaboration. #websecurity
social.security.plumbing
Frederik Braun � (@freddy@security.plumbing)
3.51K Posts, 566 Following, 1.34K Followers · 👨‍👩‍👧‍👦 Dad // 👨‍💻🛡️🦊 Security Engineer & Manager for Mozilla Firefox // ⛺🚴 Cyclist // 👨‍🎓👨‍🏫 co-founded CTF team fluxfingers in '07. // opinions are my own and I do not speak for my employer.
002
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 14/05/2025
We've written a new guide on XS-Leaks: developer.mozilla.org/en-US/docs/We… Many thanks to @freddy, Hamish Willee, @MartinaKraus11, and @terjanq for your reviews and collaboration. #websecurity
social.security.plumbing
Frederik Braun � (@freddy@security.plumbing)
3.51K Posts, 566 Following, 1.34K Followers · 👨‍👩‍👧‍👦 Dad // 👨‍💻🛡️🦊 Security Engineer & Manager for Mozilla Firefox // ⛺🚴 Cyclist // 👨‍🎓👨‍🏫 co-founded CTF team fluxfingers in '07. // opinions are my own and I do not speak for my employer.
002
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 22/04/2025
Launching the W3C Docs Community Group openwebdocs.org/content/posts/w3c-d…
openwebdocs.org
Launching the W3C Docs Community Group
Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. We are a community of web developers, standards makers, and technology companies that rely on this documentation as critical digital infrastructure, and we work cooperatively to ensure its long-term success and maintenance.
003
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 02/04/2025
Reducing the transport size of HTTP responses with a compression dictionary. New MDN article written by @tunetheweb and reviewed by Will Bamberg. developer.mozilla.org/en-US/docs/We…
webperf.social
Barry Pollard (@tunetheweb@webperf.social)
637 Posts, 226 Following, 770 Followers · Web Performance Developer Advocate for Google Chrome helping to make the web go faster! All opinions my own.
002
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 01/04/2025
W3C Docs CG As presented at the W3C Breakouts Day last week, we're considering launching a W3C Documentation Community Group. A place for technical writers, specification authors, and web developers to meet and discuss docs with the goal of providing a better understanding of web technologies […]
front-end.social
Original post on front-end.social
003
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 31/03/2025
Thank you @igalia for renewing your Open Web Docs membership and sponsoring us again in 2025! 💜 Igalia has been sponsoring OWD for the 5th time already! Sustainable funding allows us to maintain documentation in the long-term.
floss.social
Igalia (@igalia@floss.social)
597 Posts, 48 Following, 1.81K Followers · Igalia is an open source consultancy specialized in the development of innovative projects and solutions with desktop, mobile, and web technologies.
022
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 27/03/2025
We're continuing our journey through attacks and defenses on the web platform. We've now written new documentation about Cross-Site Request Forgery (CSRF) attacks: developer.mozilla.org/en-US/docs/We… Thank you @freddy for the reviews!
social.security.plumbing
Frederik Braun � (@freddy@security.plumbing)
3.34K Posts, 562 Following, 1.31K Followers · 👨‍👩‍👧‍👦 Dad // 👨‍💻🛡️🦊 Security Engineer & Manager for Mozilla Firefox // ⛺🚴 Cyclist // 👨‍🎓👨‍🏫 co-founded CTF team fluxfingers in '07. // opinions are my own and I do not speak for my employer.
000
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 27/03/2025
Thank you for becoming a monthly OWD supporter on our Open Collective, @andreu 💜 opencollective.com/open-web-docs
mastodon.andreubotella.com
Andreu Botella :verified_enby: (@andreu@andreubotella.com)
189 Posts, 46 Following, 130 Followers · Browser engineer at @igalia@floss.social, currently working on layout on Chromium (Google Chrome), as well as on interoperability between browsers and server-side JS runtimes as a co-chair of WinterTC. I'm also: - A math/physics/linguistics geek. - Linux guy. - Atheist / secular humanist. - G(r)ay asexual, as well as aromantic. - Non-binary.
000
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 25/03/2025
Tomorrow is W3C Breakouts Day! You can join online! We're leading a session to talk about documentation for web technologies and whether we need a more regular place to discuss in form of a W3C Docs Community Group. Session link […]
front-end.social
Original post on front-end.social
000
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 18/03/2025
We're happy to announce that Bloomberg joins Open Web Docs! “By supporting OWD, Bloomberg is investing in the long-term sustainability of the open web. We’re ensuring that developers have the tools they need to build, create, and maintain a healthy and accessible web for everyone.” says Alyssa […]
front-end.social
Original post on front-end.social
104
Reposted by Open Web Docs
Daniel Appelquist @torgo.mastodon.social.ap.brid.gy · 10/03/2025
Now at #FOSSBackstage: @jorydotcom & @floscholz double ack presenting the economics of @openwebdocs and about how documentation is critical digital infrastructure.
Jory and Florian stand on stage behind a podium (marked "FOSS backstage") with monitors on both sides of them reading "open web docs" and showing the first 2 rows of seating with some attendees watching.
000
Reposted by Open Web Docs
Daniel Appelquist @torgo.mastodon.social.ap.brid.gy · 10/03/2025
Good morning from Berlin, where #FOSSBackstage is kicking off! Looking forward to learning about what's "behind the scenes" with Open Source and supporting my friends @jorydotcom and @floscholz at their talk on the economics of @openwebdocs.
Street scene in Berlin - the yellow U-Bahn train in background on an elevated track over a brick building. Trucks and cars in foreground.
163
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 30/01/2025
Open Web Docs 2024 Report We're reflecting on our fourth year of ensuring the long-term health of web platform documentation openwebdocs.org/content/reports/2024
openwebdocs.org
Open Web Docs Impact and Transparency Report 2024
Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide. We are a community of web developers, standards makers, and technology companies that rely on this documentation as critical digital infrastructure, and we work cooperatively to ensure its long-term success and maintenance.
501
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 28/01/2025
Find us at #fosdem2025 this weekend! @floscholz and @torgo will be in Brussels and are happy to chat about OWD! Saturday: Tool the Docs room: fosdem.org/2025/schedule/track/docs Sunday: Funding the FOSS Ecosystem room: fosdem.org/2025/schedule/track/fund…
fosdem.org
FOSDEM 2025 - Tool the Docs
001
Open Web Docs @openwebdocs.front-end.social.ap.brid.gy · 18/12/2024
Learn about XSS for XMAS! We created a new MDN page about Cross-site scripting: developer.mozilla.org/en-US/docs/We… #websecurity
developer.mozilla.org
Cross-site scripting (XSS) - Security on the web | MDN
A cross-site scripting (XSS) attack is one in which an attacker is able to get a target site to execute malicious code as though it was part of the website.
023