3 ms·
Every? Only the ones that inject script tags pointing to external files! The content_security_policy in the manifest is for the extension, it's not added to al
by bisho 12y ago
Every? Only the ones that inject script tags pointing to external files!
The content_security_policy in the manifest is for the extension, it's not added to all the pages where the extension is active, obviously.
Also mangling the CSP by intercepting the requests to gmail is scary at best. Can't they just fetch the js from the extension and inject it rather than injecting a js with url?
Or go back to use a js bundle in the extension, which is the way it should work, because it's predictable. By fetching a script from somewhere you are adding an extra dependency on gmail that is probably far less reliable that gmail itself.