CORS for Chrome Extensions: What Actually Works
Chrome extensions live in a weird middle ground. They’re not normal web pages, but they’re not fully trusted native apps either. That matters a lot for CORS. If you build extensions long enough, you hit this fast: fetch() works in your background service worker the same request fails in a content script adding Access-Control-Allow-Origin to your request does nothing people tell you to “just use host_permissions” and then preflights still surprise you The mental model that has saved me the most time is this: ...