Hrm...
That does make things more complicated.
The dynamic nature of HTML as a whole means that 1) page contents can change interactively and 2) follow-up network requests can be made.
Limiting that would be difficult, and might require something like, spitballing here:
- Limiting extension functionality to subtractive network requests, or specifically permitted requests. Given that I've just installed LibRedirect, which points surveillanceware sites (Twitter, YT, Reddit, Instagram, etc.) to open, less-surveilled alternatives, I'm already contradicting myself here.
- Limiting extension functionality to changing displayed content after an initial pre-render has been achieved. sort of:
{ Web } <-> { Unmodified fetch } <-> { Extension } <-> { Displayed content }
That ... obviously ... fails to work for any number of
content blocking or
tracker-blocking tools (uMatrix, Ghostery, amongst others).
This leaves us with the option of tools which are audited and certified as to behaviour, have some specifically limited sets of requests, and require those back-ends to treat any such requests in specific manners which preserve privacy and confidentiality. That's a lot more cumbersome, and doesn't work off simple allow/deny rules on-device.
Thanks for the reality slap.