I suppose that if you want to disable some behavior in the website (to insert your own extension's before letting the website's own execute) you have to do that... But when would you want to do that?
I suppose that if you want to disable some behavior in the website (to insert your own extension's before letting the website's own execute) you have to do that... But when would you want to do that?
You either relax those restrictions in some way, or you can't run your code in the JS context of the page.
It's possible to run code in a content script regardless of how restrictive the pages's CSP headers are, but you are running in an isolated environment that can only access the page DOM.
For a Chrome extension using manifest v3: you can inject script tags with a src pointing to a local JS file in the extension regardless of the CSP.
Modifying the CSP is not a requirement for a Chrome extension to interact with a page's JS. I don't know about other browsers though.
In order to inject my code before theirs, I had to come up with different approaches on FF and Chrome... and since it was starting to become a cat and mouse game, I just took the extension private.
After that, they didn't escalate their game. I'm thankful for that, so that I can keep enjoying it without spending lots of time figuring out how to mess with it.