> they can inject arbitrary scripts into pages to make requests for them
disallow that behavior?
You could also just pull that code but it might change based on request origin...
disallow that behavior?
You could also just pull that code but it might change based on request origin...
That's irrelevant. If you can make changes to the page, you can exfiltrate data. The security model for addons isn't designed with restricting an addon's network activity in mind, see my other post: https://news.ycombinator.com/item?id=25623281