pichillilorenzo / flutter_inappwebview

A Flutter plugin that allows you to add an inline webview, to use a headless webview, and to open an in-app browser window.
https://inappwebview.dev
Apache License 2.0
3.22k stars 1.58k forks source link

can inappwebview bypass csp like the chrome extension? #937

Closed ozexpert closed 18 hours ago

ozexpert commented 3 years ago

Environment

Flutter version: Plugin version:
Android version:
iOS version: Xcode version:
Device information:

Description

What you'd like to happen:

Would it be possible to bypass CSP (Content Security Policy) like the chrome extensions? https://sidanmor.com/how-browser-extensions-routinely-bypass-a-csp-content-security-policy-2d482767a672?gi=5829051d7d94

Injecting javascript is meaningless if one sets a strong CSP. I tried to use the loadData() function as a workaround if the site uses strong CSP, but that would break most site's functionalities.

Is there a way to do this? or this is not possible?

github-actions[bot] commented 3 years ago

👋 @ozexpert

NOTE: This comment is auto-generated.

Are you sure you have already searched for the same problem?

Some people open new issues but they didn't search for something similar or for the same issue. Please, search for it using the GitHub issue search box or on the official inappwebview.dev website, or, also, using Google, StackOverflow, etc. before posting a new one. You may already find an answer to your problem!

If this is really a new issue, then thank you for raising it. I will investigate it and get back to you as soon as possible. Please, make sure you have given me as much context as possible! Also, if you didn't already, post a code example that can replicate this issue.

In the meantime, you can already search for some possible solutions online! Because this plugin uses native WebView, you can search online for the same issue adding android WebView [MY ERROR HERE] or ios WKWebView [MY ERROR HERE] keywords.

Following these steps can save you, me, and other people a lot of time, thanks!

github-actions[bot] commented 18 hours ago

This issue is stale and has been automatically closed because it has been open for more than 365 days with no activity. Please reopen a new issue if you still have it.