Index: chrome/renderer/chrome_content_renderer_client.cc |
diff --git a/chrome/renderer/chrome_content_renderer_client.cc b/chrome/renderer/chrome_content_renderer_client.cc |
index 3ca868a34edb163fa99ded36ff6c72c9e98b1096..a386ac0dcf94dfbad4c50a2e3da67bc21e5e79b9 100644 |
--- a/chrome/renderer/chrome_content_renderer_client.cc |
+++ b/chrome/renderer/chrome_content_renderer_client.cc |
@@ -240,6 +240,13 @@ void ChromeContentRendererClient::RenderThreadStarted() { |
// chrome-extension-resource: resources should be allowed to receive CORS |
// requests. |
WebSecurityPolicy::registerURLSchemeAsCORSEnabled(extension_resource_scheme); |
+ |
+ // chrome-extension: resources should bypass Content Security Policy checks |
+ // when included in protected resources. |
+ WebSecurityPolicy::registerURLSchemeAsBypassingContentSecurityPolicy( |
+ extension_scheme); |
+ WebSecurityPolicy::registerURLSchemeAsBypassingContentSecurityPolicy( |
+ extension_resource_scheme); |
} |
void ChromeContentRendererClient::RenderViewCreated( |