4 ms·
Very interesting if true. I'm tempted to build an extension just to check that. I wonder if a DOM mutation event would be triggered if a content script adds a
by dkopi 10y ago
Very interesting if true. I'm tempted to build an extension just to check that.
I wonder if a DOM mutation event would be triggered if a content script adds a new link element and changes it's href.
Would I be able to catch that and quickly change the href, before the content script continues to fecth the processed properties?
- AgentME 10y agoThe page could only see a mutation event and get a reference to the element if the element was attached to the document. If the extension never attaches the anchor element to the document, then the page's code can't get to it.
- dkopi 10y agoGreat point! Didn't realize that. Thanks for an informative answer. Definitely learned something new. This is why I'm here.
- gorhill 10y ago> Very interesting if true. It is true. See documentation => https://developer.chrome.com/extensions/content_scripts#execution-environment https://developer.chrome.com/extensions/content_scripts#exec... : > Content scripts execute in a special environment called an isolated world. They have access to the DOM of the page they are injected into, but not to any JavaScript variables or functions created by the page. ... The same is true in reverse
- ufmace 10y agoI don't know about this specific point, but you might want to take a look at the greasemonkey security pitfalls page [0]. There's been a lot of effort put into how all of these parts work together to make sure that malicious Javascript on the page can't interfere with what the plugin or userscript is trying to do. [0] http://archive.oreilly.com/pub/a/network/2005/11/01/avoid-common-greasemonkey-pitfalls.html http://archive.oreilly.com/pub/a/network/2005/11/01/avoid-co...
- AgentME 10y agoChrome extensions' content scripts are under stronger isolation from the page than greasemonkey scripts are (or were? -- I'm not sure if greasemonkey has changed since). Chrome extensions run in a separate "isolated world" from the page. They never share javascript objects directly. (They do share the DOM, but the isolated world gets its own separate Javascript wrappers around the DOM.) It's not possible to leak a function from the extension to the page, etc.