Chrome扩展集成Mixpanel遇CSP及模块导入错误求助
解决Chrome扩展集成Mixpanel时的CSP与模块导入错误
问题背景
用Vanilla JS搭建Chrome扩展,按官方文档集成Mixpanel(未使用NPM),出现三类错误:CSP禁止内联脚本执行、模块导入路径无法解析。
Index.html 代码
<!DOCTYPE html> <html lang="en"> <head> <script type="text/javascript"> <!-- Paste this right before your closing </head> tag --> <script type="text/javascript"> (function (f, b) { if (!b.__SV) { var e, g, i, h; window.mixpanel = b; b._i = []; b.init = function (e, f, c) { function g(a, d) { var b = d.split("."); 2 == b.length && ((a = a[b[0]]), (d = b[1])); a[d] = function () { a.push([d].concat(Array.prototype.slice.call(arguments, 0))); }; } var a = b; "undefined" !== typeof c ? (a = b[c] = []) : (c = "mixpanel"); a.people = a.people || []; a.toString = function (a) { var d = "mixpanel"; "mixpanel" !== c && (d += "." + c); a || (d += " (stub)"); return d; }; a.people.toString = function () { return a.toString(1) + ".people (stub)"; }; i = "disable time_event track track_pageview track_links track_forms track_with_groups add_group set_group remove_group register register_once alias unregister identify name_tag set_config reset opt_in_tracking opt_out_tracking has_opted_in_tracking has_opted_out_tracking clear_opt_in_out_tracking start_batch_senders people.set people.set_once people.unset people.increment people.append people.union people.track_charge people.clear_charges people.delete_user people.remove".split( " "); for (h = 0; h < i.length; h++) g(a, i[h]); var j = "set set_once union unset remove delete".split(" "); a.get_group = function () { function b(c) { d[c] = function () { call2_args = arguments; call2 = [c].concat(Array.prototype.slice.call(call2_args, 0)); a.push([e, call2]); }; } for ( var d = {}, e = ["get_group"].concat( Array.prototype.slice.call(arguments, 0)), c = 0; c < j.length; c++) b(j[c]); return d; }; b._i.push([e, f, c]); }; b.__SV = 1.2; e = f.createElement("script"); e.type = "text/javascript"; e.async = !0; e.src = "undefined" !== typeof MIXPANEL_CUSTOM_LIB_URL ? MIXPANEL_CUSTOM_LIB_URL : "file:" === f.location.protocol && "//cdn.mxpnl.com/libs/mixpanel-2-latest.min.js".match(/^\/\//) ? "https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js" : "//cdn.mxpnl.com/libs/mixpanel-2-latest.min.js"; g = f.getElementsByTagName("script")[0]; g.parentNode.insertBefore(e, g); } })(document, window.mixpanel || []); </script> </head> <body> <script type="module" src="popup.js"></script> </body> </html>
popup.js 代码
//Import Mixpanel SDK import mixpanel from "mixpanel-browser"; // Near entry of your product, init Mixpanel mixpanel.init("0000", { debug: true, track_pageview: true, persistence: "localStorage", });
控制台错误信息
index.html:12 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-6VDlGRSSdUDK2nuG1Ys7GZ0tuFVwEcvszIXy9+2ULI4='), or a nonce ('nonce-...') is required to enable inline execution. index.html:12 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'wasm-unsafe-eval' 'inline-speculation-rules' http://localhost:* http://127.0.0.1:*". Either the 'unsafe-inline' keyword, a hash ('sha256-6VDlGRSSdUDK2nuG1Ys7GZ0tuFVwEcv'), or a nonce ('nonce-...') is required to enable inline execution. index.html:1 Uncaught TypeError: Failed to resolve module specifier "mixpanel-browser". Relative references must start with either "/", "./", or "../".
解决方案
1. 修复CSP内联脚本错误
Chrome扩展默认CSP禁止内联脚本,二选一处理:
- 用脚本哈希放行:直接用控制台给出的哈希值,在
manifest.json中更新CSP:{ "manifest_version": 3, "content_security_policy": { "extension_pages": "script-src 'self' 'sha256-6VDlGRSSdUDK2nuG1Ys7GZ0tuFVwEcvszIXy9+2ULI4='; object-src 'self'" } // 其他配置项保留 } - 将内联脚本移到单独文件:把Mixpanel加载代码复制到
mixpanel-loader.js,然后在index.html中引入:
同时简化<script src="mixpanel-loader.js"></script>manifest.json的CSP:{ "manifest_version": 3, "content_security_policy": { "extension_pages": "script-src 'self'; object-src 'self'" } }
2. 修复模块导入错误
未使用NPM时,mixpanel-browser不是本地模块,无需导入——内联脚本已经把mixpanel挂载到全局window对象,直接修改popup.js:
// 删除import语句,直接使用全局mixpanel window.mixpanel.init("你的Mixpanel项目Token", { debug: true, track_pageview: true, persistence: "localStorage", });
如果不需要模块格式,也可以把index.html中的脚本标签改为普通类型:
<script src="popup.js"></script>
此时popup.js中直接写mixpanel.init(...)即可。
额外配置
如果Mixpanel需要发送请求到外部,需在manifest.json的CSP中添加允许的域名:
"content_security_policy": { "extension_pages": "script-src 'self' 'sha256-...'; object-src 'self'; connect-src 'https://api.mixpanel.com'" }
内容的提问来源于stack exchange,提问作者Samuel
相关产品推荐
相关产品推荐

