Proposal: content_security_policy.content_scripts
#95
Labels
implemented: firefox
Implemented in Firefox
neutral: safari
Not opposed or supportive from Safari
proposal
Proposal for a change or new feature
topic: csp
Related to content security policy enforcement
Since
content_scripts
run into a different context than the websites. They are not subject to the CSP of the website. To improve security, allow configuring / setting the CSP ofcontent_scripts
usingcontent_security_policy.content_scripts
. This has been worked on By Mozilla already.The implementation by Mozilla is not limited to MV3 and is also supposed to work under MV2.
See:
Mozilla Bugzilla issue 1581608
Mozilla discourse discussion
Mozilla announcement
The text was updated successfully, but these errors were encountered: