Chrome扩展Firebase弹窗登录时CSP配置遇不安全值报错求助
修复Chrome扩展Manifest V3中Cloud Identity Platform登录的CSP错误
问题场景
我按照Cloud Identity Platform官方文档的Chrome扩展登录流程配置用户登录功能,已将文档建议的URL添加至manifest.json V3的content_security_policy允许列表,配置代码如下:
"content_security_policy": { "extension_pages": "script-src 'self' https://apis.google.com https://www.gstatic.com https://www.googleapis.com https://securetoken.googleapis.com; object-src 'self';" }
加载扩展时却触发错误:
'content_security_policy.extension_pages': Insecure CSP value "https://apis.google.com" in directive 'script-src'. Could not load manifest.
尝试切换manifest版本也无法解决该问题。
修复方案
使用沙箱iframe承载登录流程,具体操作:
- 创建独立的登录页面(例如
login.html),仅用于加载Cloud Identity Platform的登录相关脚本 - 在manifest.json中为该页面配置沙箱规则,把原本放在
extension_pages中的CSP配置迁移到沙箱的content_security_policy里:"sandbox": { "pages": ["login.html"], "content_security_policy": "script-src 'self' https://apis.google.com https://www.gstatic.com https://www.googleapis.com https://securetoken.googleapis.com; object-src 'self';" } - 在扩展主页面通过iframe嵌入这个沙箱化的登录页面,完成登录交互
- 登录成功后,通过
postMessageAPI在沙箱iframe和扩展主页面之间传递用户凭证等必要信息
内容的提问来源于stack exchange,提问作者s c
相关产品推荐
相关产品推荐

