The main-world bridge was pushed into every https page as a text script. Sites that enforce Trusted Types refuse that and report the attempt to their CSP endpoint — Google's sign-in pages among them, which then have every reason to call the browser insecure. No dapp lives on those origins: a static list of the big enforcing sites is skipped outright, any other origin that rejects the bridge once is remembered and skipped from then on, and where Trusted Types exist unenforced a policy keeps the assignment clean. |
||
|---|---|---|
| .. | ||
| lib | ||
| addon.json | ||
| electrum-servers.json | ||
| index.js | ||
| panel.html | ||
| panel.js | ||
| qr.js | ||
| wallet-inject.js | ||