【发布时间】:2021-07-30 00:02:49
【问题描述】:
我正在尝试在页面中加载(注入)javascript 代码。 javascript 文件是扩展的本地文件。文件路径是 'js/somefile.js'。
const basePath = chrome.runtime.getURL('');
fetch(chrome.runtime.getURL(filePath), { mode: 'same-origin' }) // <-- important
.then((_res) => _res.blob())
.then((_blob) => {
const reader = new FileReader();
reader.addEventListener('loadend', (data) => {
callback(data.currentTarget.result, basePath);
});
reader.readAsText(_blob);
});
const scriptTag = document.createElement('script');
scriptTag.innerHTML = scriptText;
scriptTag.type = 'text/javascript';
const scriptElement = document[injectLocation].appendChild(scriptTag);
if (removeImmediately) document[injectLocation].removeChild(scriptElement);
我的网络可访问资源是:
"web_accessible_resources": [{
"resources": [
"js/*.js",
],
"matches": ["<all_urls>"]
}],
"content_security_policy": {
"extension_pages": "script-src 'self'; object-src 'self'",
"sandbox": "sandbox allow-scripts; script-src 'self' 'https://apis.google.com/' 'https://www.gstatic.com/' 'https://*.firebaseio.com' 'https://www.googleapis.com' 'https://ajax.googleapis.com'; object-src 'self'"
},
我得到的错误是:
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-Wq/CW2mxkri68TjkuaA0+LnU0capVpyiEuSA5NOVNfU='), or a nonce ('nonce-...') is required to enable inline execution.
【问题讨论】:
-
您显示的代码与错误无关,即您有一个内联脚本,这是弹出窗口或选项页面中的常见问题:more info。
-
你是对的,确实我正在尝试在页面中注入所述脚本。我看到 executeScript 是一个可行的替代方案。如何在当前选项卡中注入脚本代码?
-
我用有问题的行更新了代码。因为 V3 不允许注入脚本,所以阻塞的是 appendchild 部分。我正在使用内容脚本来执行此操作,但仍然失败。
-
目前您使用内容脚本在page context 中注入另一个脚本,这是从页面中提取/访问JS变量/函数所需的非常特殊的东西。要注入你不需要的代码。只需将 js 文件作为内容脚本注入(以声明方式或通过 executeScript)。
标签: javascript google-chrome-extension chrome-extension-manifest-v3