3 ms·
hmm, they don't mention `eval()` being blocked in executed functions. Is it mentioned elsewhere? Also, can't executed function just add `<script>` tag with giv
by Lex-2008 5y ago
hmm, they don't mention `eval()` being blocked in executed functions. Is it mentioned elsewhere?
Also, can't executed function just add `<script>` tag with given `src`?
- teraflop 5y agoIt's not mentioned in this page or the Manifest V3 design document[1], but buried in the "Migrating to Manifest V3" article[2], there's a slightly cryptic note: > In addition, MV3 disallows certain CSP modifications for extension_pages that were permitted in MV2. The script-src, object-src, and worker-src directives may only have the following values: self; none; Any localhost source, (http://localhost http://localhost, http://127.0.0.1 http://127.0.0.1, or any port on those domains) In other words, scripts with access to the extension APIs are no longer allowed to specify the "unsafe-eval" CSP, and so they can no longer call eval(). [1]: https://docs.google.com/document/d/1nPu6Wy4LWR66EFLeYInl3NzzhHzc-qnk4w4PX-0XMw8/edit https://docs.google.com/document/d/1nPu6Wy4LWR66EFLeYInl3Nzz... [2]: https://developer.chrome.com/docs/extensions/mv3/intro/mv3-migration/ https://developer.chrome.com/docs/extensions/mv3/intro/mv3-m...
- ROARosen 5y agoSee here: https://news.ycombinator.com/item?id=27442622 https://news.ycombinator.com/item?id=27442622