But you have all the code and you know which functions/methods/etc that can do requests so it should be trivial... either way, if it is not a solvable problem, there is a major problem in the design.
but you can't. See the last part of my comment: "they can inject arbitrary scripts into pages to make requests for them".
>either way, if it is not a solvable problem, there is a major problem in the design.
Not really. It's like complaining that debuggers can impersonate programs they attach themselves to.
disallow that behavior?
You could also just pull that code but it might change based on request origin...
That's irrelevant. If you can make changes to the page, you can exfiltrate data. The security model for addons isn't designed with restricting an addon's network activity in mind, see my other post: https://news.ycombinator.com/item?id=25623281