but you can't. See the last part of my comment: "they can inject arbitrary scripts into pages to make requests for them".
>either way, if it is not a solvable problem, there is a major problem in the design.
Not really. It's like complaining that debuggers can impersonate programs they attach themselves to.
disallow that behavior?
You could also just pull that code but it might change based on request origin...
That's irrelevant. If you can make changes to the page, you can exfiltrate data. The security model for addons isn't designed with restricting an addon's network activity in mind, see my other post: https://news.ycombinator.com/item?id=25623281
This ends up effect as magically determining where it’ll call, with a lot less work.
And this was Google Play verified with a million downloads.