Slide 16
Slide 16 text
16
9.1. Vendor-specific Extensions and Addons
Policy enforced on a resource SHOULD NOT interfere with the operation of user-
agent features like addons, extensions, or bookmarklets. These kinds of features
generally advance the user’s priority over page authors, as espoused in [HTML-
DESIGN].
http://www.w3.org/TR/CSP3/#extensions
… we model extensions more or less as an application of the user's will, and … we
prioritize the user above the site. This means that the extension is explicitly allowed to
do things that the site owner would prefer that it not do.
https://bugs.chromium.org/p/chromium/issues/detail?id=634265