chrome extension manifest 3 https://apis.google.com

Viewed 255

This line in manifest 3

 "content_security_policy": {
    "extension_pages": "script-src 'self'; script-src-elem 'self' https://apis.google.com; object-src 'self';"
  },

Gives me error

Refused to load the script 'https://apis.google.com/js/api.js?onload=__iframefcb41660' because it violates the following Content Security Policy directive: "script-src 'self'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

I'm using google api for authentication with firebase. In manifest v2 all was fine.

1 Answers

You cannot use external scripts in manifest V3, everything should be inside the extension.

Try using a fetch() if it's an API endpoint.

Related