You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何Chrome扩展的content_script无法注入Blob URL页面?

问题场景

以下示例HTML:

<html>
    <head>
        <script>
            let blob = new Blob(["<html>Blob content!</html>"], {type: 'text/html'});
            let blobUrl= URL.createObjectURL(blob);
            window.location.href = blobUrl;
        </script>
    </head>
    <body>
        Initial Page
    </body>
</html>

会生成一个内容为<html>Blob content!</html>的新HTML页面,该页面的URL为:blob:null/c608e557-cacb-4bec-bce2-1f68c6315415

我有一个Chrome扩展,其manifest.json配置大致如下:

"content_scripts": [{
    "matches": ["<all_urls>"],
    "match_origin_as_fallback": true,
    "run_at": "document_idle",
    "js": ["getPage.js"],
    "all_frames": true
}]
问题

为何Chrome扩展中的content_script脚本getPage.js无法注入到该Blob URL页面中?

原因解析
  • Blob URL的null源限制:该Blob页面的URL源为null,Chrome扩展的<all_urls>匹配规则并不包含null源的页面,即便设置了match_origin_as_fallback也无法突破这个限制。
  • 安全隔离机制:Chrome对null源的页面有特殊的安全隔离策略,内容脚本默认不会注入这类无有效可信源的页面,以此避免潜在的安全风险,防止脚本被注入到不受管控的孤立内容中。
  • 匹配规则的局限性:<all_urls>实际覆盖的是带有有效协议(如http、https、ftp等)的常规URL,blob:协议的URL虽被部分支持,但当它的源为null时,不在常规匹配范围内;而match_origin_as_fallback仅在源无法正常解析时生效,null源是明确的无效状态,不会触发该 fallback 逻辑。

内容的提问来源于stack exchange,提问作者Simon S.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 13:27:20