A browser extension can see and alter pages outside its own origin. That capability makes host grants, page selectors, background events, and messages part of one trust design. This track follows a permit checklist helper from the user gesture to an authorized server operation. It makes denial and site changes ordinary states and keeps a page’s text from becoming extension authority.
Topics in this track
- Extension Host Permissions and User Invocation — Give an extension access only to the site and action its user requested.
- Content Script Isolation and DOM Mutation — Read page data as untrusted input and keep extension UI stable as the document changes.
- Extension Background Events and Durable State — Persist task state across worker shutdown and browser restart without replaying effects.
- Extension Message Contracts and Page Data Boundary — Validate messages between the page, content script, background worker, and server.
Prerequisite paths
Browser Security and Data Stewardship; Embedded Interfaces and Cross-Window Contracts; Background Workflow Reliability.
Practice path
Build Project: permit checklist browser helper and check decisions in Web Development: extension boundary decisions quiz.
