You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Chrome扩展弹窗偶发Firebase CSP错误,寻求解决方案

Chrome扩展Manifest V3弹窗Firebase CSP问题及身份识别疑惑

问题现象

  • 原本正常运行的Chrome扩展弹窗,使用一段时间后出现Firebase相关CSP错误;移除并重新添加扩展后错误暂时消失,且仅在popup.html中出现该问题。
  • 具体错误信息:

BrowserPollConnection.ts:740 Refused to load the script 'https://fb-instance.firebaseio.com/.lp?start=t&ser=xx&cb=3&v=5&p=1:xxx' because it violates the following Content Security Policy directive: "script-src 'self' 'wasm-unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

当前配置与尝试

  • 扩展使用Manifest V3版本,已在manifest.json中配置extension_pages的CSP规则:
"content_security_policy": {
  "extension_pages": "script-src 'self'; object-src 'self'; script-src-elem 'self' 'unsafe-inline' https://www.gstatic.com/ https://*.firebaseio.com https://*.firebasedatabase.app https://www.googleapis.com"
},
  • 调整CSP规则后问题仍未解决,不愿采用sandbox CSP方案(需重构弹窗代码,且无法访问chrome.window、chrome.tabs等API)
  • 错误触发前无firebaseio.com相关请求,触发后持续出现;重载扩展无效,仅移除并重新添加扩展可暂时解决
  • 当前Firebase版本为^9.6.3

已定位的解决方法及疑惑

  • 已定位问题与Firebase的onAuthStateChanged相关,改为从后台获取auth.uid后可正常操作
  • 疑惑:弹窗未执行firebase.initializeApp(config),但Firebase仍能识别身份

内容的提问来源于stack exchange,提问作者TrySpace

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 10:18:39