| Index: extensions/renderer/extension_injection_host.cc
|
| diff --git a/extensions/renderer/extension_injection_host.cc b/extensions/renderer/extension_injection_host.cc
|
| index ec75068ed1244a1eb31fbcb240ccedf80accbaac..16b0831b6e2f4bd72537678c6d324fd450ff0ced 100644
|
| --- a/extensions/renderer/extension_injection_host.cc
|
| +++ b/extensions/renderer/extension_injection_host.cc
|
| @@ -57,10 +57,8 @@
|
|
|
| blink::WebSecurityOrigin top_frame_security_origin =
|
| render_frame->GetWebFrame()->top()->securityOrigin();
|
| - // Only whitelisted extensions may run scripts on another extension's page.
|
| if (top_frame_security_origin.protocol().utf8() == kExtensionScheme &&
|
| - top_frame_security_origin.host().utf8() != extension_->id() &&
|
| - !PermissionsData::CanExecuteScriptEverywhere(extension_))
|
| + top_frame_security_origin.host().utf8() != extension_->id())
|
| return PermissionsData::ACCESS_DENIED;
|
|
|
| // Declarative user scripts use "page access" (from "permissions" section in
|
|
|