Skip to content

Commit 2db1ea7

Browse files
committed
feat: manifest CSP
1 parent 42968c7 commit 2db1ea7

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

background.js

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,8 @@ chrome.webRequest.onHeadersReceived.addListener(({ responseHeaders, url }) => {
1212
for (let p of cspAllowAll) {
1313
csp.value = csp.value.replace(`${p}`, `${p} * blob: data:`); // * does not include data: URIs
1414
}
15+
// Discord doesn't even specify a manifest CSP so we create our own
16+
csp.value += ' manifest-src * blob: data:;'
1517

1618
// Fix Discord's broken CSP which disallows unsafe-inline due to having a nonce (which they don't even use?)
1719
csp.value = csp.value.replace(/'nonce-.*?' /, '');

0 commit comments

Comments
 (0)