Extensions: Enforce secure extension page CSP for extensions using csp dictionary.
This CL enforces a secure extension page CSP for any extension using the "content_security_policy" dictionary key and for all manifest V3 extensions. The restrictions placed are same as those for secure isolated world CSPs. This should facilitate preventing these extensions from loading remote scripts. BUG=993530 Change-Id: I66191e7688a772eb0cf8321f09370d6dba4b0cb4 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1753470 Commit-Queue: Karan Bhatia <karandeepb@chromium.org> Reviewed-by:Devlin <rdevlin.cronin@chromium.org> Cr-Commit-Position: refs/heads/master@{#688230}
Showing
File moved
File moved
Please register or sign in to comment