#1244: [wg/webappsec] Web Application Security Working Group Charter

Visit on Github

Opened Jul 4, 2026

This issue was created because the 'horizontal review requested' label was added to § https://github.com/w3c/strategy/issues/551

This review is requested prior to the Advisory Committee Review.

New charter proposal, reviewers please take note.

Charter Review

Web Application Security Working Group Charter

diff from charter template

Expected end of charter refinement phase: unknown

diff from previous charter

chair dashboard

What kind of charter is this? Check the relevant box / remove irrelevant branches.

  • Existing WG recharter

Horizontal Reviews: apply the Github label "Horizontal review requested" to request reviews for accessibility (a11y), internationalization (i18n), privacy, security, and TAG. Also add a "card" for this issue to the Strategy Funnel.

Substantive changes

N/A

Communities suggested for outreach

Known or potential areas of concern

Where would charter proponents like to see issues raised? (this strategy funnel issue)

Anything else we should think about as we review?

@dveditz @mikewest

Charter facilitator(s)

cc @simoneonofri

<!-- Content below this is maintained by @w3c-tag-bot -->

Track conversations at https://tag-github-bot.w3.org/gh/w3ctag/design-reviews/1244

Discussions

Log in to see TAG-private discussions.

Discussed Jul 13, 2026 (See Github)

Heather: There are no deliverable dates. Is that expected?

Marcos: Fair question to ask them now.

Heather: Also noted they have two discovery items; we should watch that. Also, they reordered alphabetically, which makes the diff useless.

Marcos: They should hold off on reordering until after the review. Will post the questions.

Comment by @marcoscaceres Jul 15, 2026 (See Github)

Two quick questions:

  1. How come there's no Expected Completions dates? (not a TAG concern, but we were wondering?)
  2. Would you mind restoring the original order of the deliverables (just for review)... it makes it hard to see what's changed in the diff. Would be really helpful, just for now, to put things back in the previous order - then the WG can change the order on publication.
Discussed Jul 20, 2026 (See Github)

skip

Comment by @simoneonofri Jul 24, 2026 (See Github)

@marcoscaceres, thank you for the comment, follow-up below:

  1. I restored the 2024 order of the normative deliverables. The update was merged in w3c/charter-drafts#855, so the diff should now be easier to review.
  2. I checked the public WebAppSec tracking for expected completion dates. There are active Candidate Recommendation preparation issues for Web Cryptography Level 2, Subresource Integrity Level 2, Fetch Metadata, and Content Security Policy Level 3, but none currently records a target date or dated milestone. I therefore kept those entries as Undetermined rather than adding speculative dates.
Discussed Aug 3, 2026 (See Github)

Marcos: Haven't looked in a while but think we're pretty much done.

Brian: Can probably close

Marcos: I'll take a look now but think we're OK with it.

Comment by @marcoscaceres Aug 5, 2026 (See Github)

Thanks for the wait. We've completed our review and the TAG is satisfied with no concerns. The only minor thing that stood out was that for "Device Bound Session Credentials for Single Sign-On " the WG should probably coordinate with the FedID WG. Further, it might be good to explicitly list FedID as group that Web App Sec coordinates with in Section 5.1. There's a lot of collaboration happening already across the two groups because of Digital Credentials, given it builds on Cred Man.