aboutsummaryrefslogtreecommitdiff
path: root/ext/manifest.json
diff options
context:
space:
mode:
authortoasted-nutbread <toasted-nutbread@users.noreply.github.com>2020-09-18 21:16:39 -0400
committerGitHub <noreply@github.com>2020-09-18 21:16:39 -0400
commit2f4adbab2cbefba1898b4ce6f8ff5e03622cfd34 (patch)
tree3c93a79e9f426b53ad30db0906b3b73d25834afc /ext/manifest.json
parente9d6c4cc928516647172c5ba3c938126390adfa2 (diff)
Handlebars sandbox (#612)
* Set up template renderer proxy * Use proxy * Remove unused handlebars script tags * Update manifest
Diffstat (limited to 'ext/manifest.json')
-rw-r--r--ext/manifest.json9
1 files changed, 8 insertions, 1 deletions
diff --git a/ext/manifest.json b/ext/manifest.json
index 271f6e62..59c88072 100644
--- a/ext/manifest.json
+++ b/ext/manifest.json
@@ -66,6 +66,12 @@
"page": "bg/settings.html",
"open_in_tab": true
},
+ "sandbox": {
+ "pages": [
+ "bg/template-renderer.html"
+ ],
+ "content_security_policy": "sandbox allow-scripts; script-src 'self' 'unsafe-eval'; object-src 'self'"
+ },
"permissions": [
"<all_urls>",
"storage",
@@ -93,7 +99,8 @@
}
},
"web_accessible_resources": [
- "fg/float.html"
+ "fg/float.html",
+ "bg/template-renderer.html"
],
"content_security_policy": "script-src 'self' 'unsafe-eval'; object-src 'self'",
"applications": {