3 ms·
This is fixed in manifest_version 2: "A package's resources are no longer available by default to external websites (as the src of an image, or a script tag).
by abarth 15y ago
This is fixed in manifest_version 2:
"A package's resources are no longer available by default to external websites (as the src of an image, or a script tag). If you want a website to be able to load a resource contained in your package, you'll need to explicitly whitelist it via the web_accessible_resources manifest attribute."
http://code.google.com/chrome/extensions/dev/manifestVersion.html http://code.google.com/chrome/extensions/dev/manifestVersion...
See <http://blog.chromium.org/2012/02/more-secure-extensions-by-default.html> http://blog.chromium.org/2012/02/more-secure-extensions-by-d...; for information about other security improvements in manifest_version 2.
- aboodman 15y agomanifest version 2 is not backward compatible, so most extensions should not update yet. When Chrome 18 is deployed to the stable channel, we will update the docs and begin slowly encouraging developers to transition. In the shorter term, developers who want to prevent their extensions from being trivially detected can use the web_accessible_resources property instead: http://code.google.com/chrome/extensions/dev/manifest.html#web_accessible_resources http://code.google.com/chrome/extensions/dev/manifest.html#w.... This property is available in Chrome 19 and higher and is ignored in older versions.