ืคื’ื™ืขื•ืช ื”ืžืืคืฉืจืช ืœืชื•ืกืคื•ืช Chrome ืœื”ืคืขื™ืœ ืงื•ื“ ื—ื™ืฆื•ื ื™ ืœืžืจื•ืช ื”ืจืฉืื•ืช

ื™ืฆื ืœืื•ืจ ืฉื™ื˜ื” ื”ืžืืคืฉืจืช ืœื›ืœ ืชื•ืกืฃ Chrome ืœื”ืคืขื™ืœ ืงื•ื“ JavaScript ื—ื™ืฆื•ื ื™ ืžื‘ืœื™ ืœื”ืขื ื™ืง ืœืชื•ืกืคืช ื”ืจืฉืื•ืช ืžื•ืจื—ื‘ื•ืช (ืœืœื unsafe-eval ื•-unsafe-inline ื‘-manifest.json). ื”ื”ืจืฉืื•ืช ืžืจืžื–ื•ืช ื›ื™ ืœืœื eval unsafe ื”ืชื•ืกืฃ ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืจืง ืงื•ื“ ืฉื ื›ืœืœ ื‘ื”ืคืฆื” ื”ืžืงื•ืžื™ืช, ืืš ื”ืฉื™ื˜ื” ื”ืžื•ืฆืขืช ืžืืคืฉืจืช ืœืขืงื•ืฃ ืžื’ื‘ืœื” ื–ื• ื•ืœื”ืคืขื™ืœ ื›ืœ JavaScript ืฉื ื˜ืขืŸ ืžืืชืจ ื—ื™ืฆื•ื ื™ ื‘ื”ืงืฉืจ ืฉืœ ื”ืชื•ืกืคืช- ืขึทืœ.

ื’ื•ื’ืœ ืกื’ืจื” ื›ืขืช ืืช ื”ื’ื™ืฉื” ืœืฆื™ื‘ื•ืจ ื“ื•ื— ื‘ืขื™ื•ืช, ืื‘ืœ ื‘ืืจื›ื™ื•ืŸ ื”ืฉืชืžืจ ืงื•ื“ ืœื“ื•ื’ืžื” ื›ื“ื™ ืœื ืฆืœ ืืช ื”ื‘ืขื™ื”. ื“ึถืจึถืš ื“ื•ึนืžึถื” ืฉื™ื˜ื” ืœืขืงื•ืฃ ืืช ืžื’ื‘ืœืช ื”-script-src 'self' ื‘-CSP ื•ืžืกืชื›ืžืช ื‘ื”ื—ืœืคืช ืชื’ ืกืงืจื™ืคื˜ ื“ืจืš document.createElement('script') ื•ืœื›ืœื•ืœ ื‘ื• ืชื•ื›ืŸ ื—ื™ืฆื•ื ื™ ื‘ืืžืฆืขื•ืช ืคื•ื ืงืฆื™ื™ืช ื”ืื—ื–ื•ืจ, ื•ืœืื—ืจ ืžื›ืŸ ื”ืงื•ื“ ื™ื‘ื•ืฆืข ื‘- ื”ื”ืงืฉืจ ืฉืœ ื”ืชื•ืกืฃ ืขืฆืžื•.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”