You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Chrome扩展Content Security Policy配置修改后仍报错求助

Troubleshooting Your Chrome Extension CSP Error

Hey there, let's break down why you're still hitting Content Security Policy (CSP) issues even after adjusting your manifest, and how to fix it.

First off, a critical point: your manifest uses Manifest V2, which Chrome has fully deprecated starting with version 115. Newer Chrome builds block V2 extensions entirely, so even if your CSP config looks correct, the browser might be ignoring it because of the outdated manifest version. That's likely a major factor behind your persistent errors.

Let's walk through the fixes step by step:

1. Upgrade to Manifest V3 (Non-Negotiable for New Chrome Versions)

Manifest V3 is now the only supported format for Chrome extensions. Here's how to adjust your manifest to comply:

{
  "manifest_version": 3,
  "name": "MyExtensionPrice",
  "description": "MyExtension",
  "version": "1.0",
  "action": {
    "default_icon": "icon.png",
    "default_popup": "popup.html"
  },
  "content_security_policy": {
    "extension_pages": "script-src 'self'; object-src 'self';"
  }
}

Note that V3's CSP structure is different—we use the extension_pages key, and remote scripts (like https://ajax.googleapis.com) are not allowed in extension pages (popup, options page, etc.) by default. This aligns with your suspicion that Chrome's new versions restrict external resources.

2. Localize Remote Scripts

Since V3 blocks remote script sources in extension pages, you'll need to download any external libraries (like jQuery from Google's CDN) directly into your extension folder. For example:

  • Download jquery.min.js and save it in your extension directory
  • Update your popup.html to reference the local file instead of the remote URL:
    <script src="jquery.min.js"></script>
    

This avoids CSP conflicts entirely and keeps your extension compliant with modern Chrome rules.

3. Remove Inline Scripts

If your popup.html has any inline <script> blocks (code written directly in the HTML file), these will trigger CSP errors even with a correct manifest. Move all inline code to a separate .js file (e.g., popup.js) and reference it in your HTML:

<script src="popup.js"></script>

4. Clear Extension Cache

Sometimes Chrome caches old extension configurations, leading to lingering errors even after you've fixed the manifest. Try these steps to refresh:

  • Go to chrome://extensions/
  • Enable Developer Mode (toggle in the top-right corner)
  • Find your extension, click "Remove", then reload it by dragging the extension folder into the extensions page
  • Click the "Update" button (refresh icon) to ensure the latest manifest is loaded

Why Your Original V2 Config Might Still Fail

Even if you stick with V2 (not recommended, since it's officially unsupported), newer Chrome versions enforce stricter CSP rules for V2 extensions. For example, some remote script sources that worked in older versions may now be blocked, and inline scripts require explicit 'unsafe-inline' in your CSP (though this is not secure).

Putting it all together, upgrading to V3 and localizing your resources should resolve the persistent CSP errors you're seeing.

内容的提问来源于stack exchange,提问作者DemonSlayer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 04:19:30