Refused to apply inline style because it violates the following Content Security Policy directive

后端 未结 6 2364
心在旅途
心在旅途 2020-12-08 09:08

So, in about 1 hour my extensions failed hard.

I was doing my extension and it was doing what I pretended. I made some changes, and as I didnt liked I deleted them,

6条回答
  •  南笙
    南笙 (楼主)
    2020-12-08 09:43

    You can also relax your CSP for styles by adding style-src 'self' 'unsafe-inline';

    "content_security_policy": "default-src 'self' style-src 'self' 'unsafe-inline';" 
    

    This will allow you to keep using inline style in your extension.

    Important note

    As others have pointed out, this is not recommended, and you should put all your CSS in a dedicated file. See the OWASP explanation on why CSS can be a vector for attacks (kudos to @ KayakinKoder for the link).

提交回复
热议问题