mirror of
https://github.com/bitwarden/browser
synced 2025-12-11 22:03:36 +00:00
fix: enable dynamic URLs for Chrome web accessible resources (#17429)
This commit adds use_dynamic_url: true to the extension's web_accessible_resources configuration. When enabled, Chrome generates random session-based GUIDs for extension resource URLs instead of using the predictable static extension ID. This enhances privacy by making extension resource URLs unpredictable and prevents third-party enumeration of installed extensions. The feature is supported in Chrome 102+ and changes resource URLs from chrome-extension://[static-id]/resource to chrome-extension://[random-guid]/resource, with GUIDs regenerating each browser session while maintaining all existing extension functionality. Addresses: https://bitwarden.atlassian.net/browse/PM-28344
This commit is contained in:
@@ -164,7 +164,8 @@
|
|||||||
"overlay/menu.html",
|
"overlay/menu.html",
|
||||||
"popup/fonts/*"
|
"popup/fonts/*"
|
||||||
],
|
],
|
||||||
"matches": ["<all_urls>"]
|
"matches": ["<all_urls>"],
|
||||||
|
"use_dynamic_url": true
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"__firefox__browser_specific_settings": {
|
"__firefox__browser_specific_settings": {
|
||||||
|
|||||||
Reference in New Issue
Block a user