Removed done(), added some comments explaining the change
Stephanie Ding committed
Sep 11, 2019 at 08:05 UTC
2e75000f404ec7810fac03420b2e2cf215baa69d
2 files changed
+8
-8
packages/react-devtools-extensions/src/injectGlobalHook.js
+5
-1
@@ -31,8 +31,12 @@ window.addEventListener('message', function(evt) {
31
reactBuildType: evt.data.reactBuildType,
32
};
33
chrome.runtime.sendMessage(lastDetectionResult);
34
+
35
+ // Inject the backend. This is done in the content script to avoid CSP
36
+ // and Trusted Types violations, since content scripts can modify the DOM
37
+ // and are not subject to the page's policies
38
} else if (evt.data.source === 'react-devtools-inject-backend') {
35
- //Inject the specified script
39
+ // the prototype stuff is in case document.createElement has been modified
40
var script = document.constructor.prototype.createElement.call(document, 'script');
41
script.src = chrome.runtime.getURL('build/backend.js');
42
script.charset = "utf-8";
packages/react-devtools-extensions/src/main.js
+3
-7
@@ -138,14 +138,10 @@ function createPanelIfReactLoaded() {
138
chrome.devtools.inspectedWindow.eval(
139
`window.postMessage({ source: 'react-devtools-inject-backend' });`,
140
function(response, error) {
141
- if (error) {
142
- console.log(error);
143
- }
144
-
145
- if (typeof done === 'function') {
146
- done();
141
+ if (error) {
142
+ console.log(error);
143
+ }
144
}
148
- }
145
);
146
147
const viewElementSourceFunction = createViewElementSource(