4 ms·
Having to circumvent your own extension policy that prevents tracking in order prevent the tracking you were doing is not the best way to look competitive.
by byecomputer 6y ago
Having to circumvent your own extension policy that prevents tracking in order prevent the tracking you were doing is not the best way to look competitive.
- resoluteteeth 6y agoIt's not "circumventing" a "policy." Injecting html is what you're supposed to do in this situation because it's safer than allowing contentscripts to directly execute javascript in the page context. This is how all chrome extensions do it.
- chrismorgan 6y agoInjecting HTML is a terrible idea. It has extreme overhead compared to just evaluating some JavaScript in the page context, and it will break the occasional page that expects certain things of its DOM, and it’s fairly inevitably broken when you have CSP things. The DOM belongs to the document. You shouldn’t touch it unless you actually have to to provide your functionality, and this isn’t such an extension. There’s a a proper mechanism for executing scripts in the document context, which should be used.
- resoluteteeth 6y ago> There’s a a proper mechanism for executing scripts in the document context, which should be used. Which is? Edit: In the interest of saving time, it looks based on your other comment that you're referring to chrome.tabs.executescript, but code executed this way executes as a content script so it doesn't run in the page context and can't communicate with javascript running on the page. If there's another way of running code in the page without injecting html I'd love to hear about it, though.
- byecomputer 6y agoThey could always try asking me if I want to be tracked, no code injection necessary.