Earlier quoted context omitted.
MV3 splits permissions into host permissions and classical permissions (tabs, storage, etc). Putting in your host permission list means that whatever the extension does, it can do it on all possible urls you may visit in the browser. In this sense, it's no different than in MV2. What's different is the classical permissions. Previously you could use the webRequest permission to execute custom JS functions in response…
> Basically, Google is full of shit. Not completely full of shit. Declarative rules are a good idea in the general case. Random browser extensions really should not have unrestricted access to the network requests. This is how we get malware. It's just that uBlock Origin is so important and trusted that these limitations should not apply to it. I'd even say ad blockers should be a built in browser feature but the con…
The heavily depends and I would disagree here. Yes, JS execution is unpopular, but it enables you to make your app behave like you want to. Otherwise it behaves like Google wants to. Google is no scammer at least, but the end result is suboptimal.