# Content.js now need permissions on each matching URL

**URL:** <https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164>\
**Category:** Development\
**Created:** [November 13, 2024, 7:28am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164 "2024-11-13T07:28:39Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 7:28am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/1 "2024-11-13T07:28:39Z")

</div>

For example my [https://ff.chatgptautocontinue.com](https://ff.chatgptautocontinue.com) and [https://ff.chatgptwidescreen.com](https://ff.chatgptwidescreen.com) now has a blue dot on the toolbar icon, then only when user clicks, do the content.js load on [chatgpt.com](http://chatgpt.com)

Pre-click:

 ![image](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/a/a/aa3d732ed19c7cfe4175a8fe029502aff89442d3.png)  
 ![image](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/e/7/e797b29ea83fc0d2f92c1351426ed67e1c48822c.png)

Post-click:

 ![image](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/7/a/7ae4d65908764a8a5b3ce7494fa0df377067bb73.png)

This is very bad for UX, how to fix?

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [November 13, 2024, 7:49am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/2 "2024-11-13T07:49:38Z")

</div>

The dot is shown when your addon “want’s” to run on the current page but doesn’t have the host permission for doing that.  
For example, when the host is listed in the `optional_host_permissions` list. This was introduced only recently:

> **[1851083 - Manifest V3 extensions with activeTab/tabs permission require user...](https://bugzilla.mozilla.org/show_bug.cgi?id=1851083#c13)**
>
> VERIFIED (lgreco) in WebExtensions - General. Last updated 2024-07-17.

To fix it, you need put the host to the host permissions array:

> **[host\_permissions - Mozilla | MDN](https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/host_permissions)**
>
> Use the host\_permissions key to request access for the APIs in your extension that read or modify host data, such as cookies, webRequest, and tabs. This key is an array of strings, and each string is a request for a permission.

Also, content scripts registered through the manifest file will automatically get the host permission.

---

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 8:17am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/3 "2024-11-13T08:17:22Z")

</div>

Sup @juraj.masiar, thank you for trying to help, you are a true Friend of Add-ons!

I tested adding ` "host_permissions": ["https://chatgpt.com/*"],` but it didn’t work, also the post you linked was last updated 2024-07-17, and I never had blue dot problem until recently (extension was published in September, after July)

Also you said “content scripts registered through the manifest file will automatically get the host permission” anyway and my `content_scripts` is already:

```auto
  "content_scripts": [{
    "matches": ["https://chatgpt.com/*", "https://www.perplexity.ai/*", "https://poe.com/*"],
    "run_at": "document_end", "js": ["content.js"]
  }],

```

…and this problem doesn’t occur in Chrome, so all this leads me to believe a recent FF update is the culprit

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [November 13, 2024, 9:17am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/4 "2024-11-13T09:17:18Z")

</div>

You are a funny man, thanks! 😃

Could you post the whole manifest file here?  
Also, any chance you are removing host permissions using code? 🙂

The dot issue still exists, for example if you have optional `<all_urls>` permission.

But it sounds super strange… the dot should only appear when you don’t have host permission for the currently viewed page, so are you sure the tab URL is `chatgpt.com`?

Also, I’ve just tested it in one of my MV3 addons, removing host from `host_permissions` array doesn’t break it for the host as long as the content script is registered for the host.

---

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 9:25am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/5 "2024-11-13T09:25:27Z")

</div>

> [@juraj.masiar](#):
>
> Could you post the whole manifest file here?

Yes it is @ [chatgpt-widescreen/firefox/extension/manifest.json at main · adamlui/chatgpt-widescreen · GitHub](https://github.com/adamlui/chatgpt-widescreen/blob/main/firefox/extension/manifest.json)

```js
{
  "manifest_version": 3,
  "name": " __MSG_appName__",
  "short_name": "ChatGPT 🖥️",
  "description": " __MSG_appDesc__",
  "version": "2024.11.12",
  "author": "Adam Lui",
  "homepage_url": "https://www.chatgptwidescreen.com",
  "default_locale": "en",
  "icons": {
    "16": "icons/icon16.png",
    "32": "icons/icon32.png",
    "48": "icons/icon48.png",
    "64": "icons/icon64.png",
    "128": "icons/icon128.png",
    "223": "icons/icon223.png"
  },
  "permissions": ["activeTab", "storage"],
  "action": { "default_popup": "popup/index.html" },
  "web_accessible_resources": [{
    "matches": ["<all_urls>"],
    "resources": ["lib/chatgpt.js", "lib/dom.js", "lib/settings.js"]
  }],
  "content_scripts": [{
    "matches": ["https://chatgpt.com/*", "https://www.perplexity.ai/*", "https://poe.com/*"],
    "run_at": "document_end", "js": ["content.js"]
  }],
  "background": { "scripts": ["background.js"]},
  "browser_specific_settings": {
    "gecko": { 
      "id": "chatgpt.widescreen@chatgptevo.com",
      "strict_min_version": "109.0"
    }
  }
}

```

> [@juraj.masiar](#):
>
> Also, any chance you are removing host permissions using code? 🙂

No I don’t believe so

> [@juraj.masiar](#):
>
> The dot issue still exists, for example if you have optional `<all_urls>` permission.

I tested using both `<all_urls>` and `https://chatgpt.com/*` for `host_permissions` but no dice

> [@juraj.masiar](#):
>
> But it sounds super strange… the dot should only appear when you don’t have host permission for the currently viewed page, so are you sure the tab URL is `chatgpt.com` ?

Indeed the root domain is [chatpgt.com](http://chatpgt.com), also same new problem occurs on perplexity.ai

> [@juraj.masiar](#):
>
> Also, I’ve just tested it in one of my MV3 addons, removing host from `host_permissions` array doesn’t break it for the host as long as the content script is registered for the host.

My `content_scripts` includes `matches` for all 3 AI sites the content.js is intended to run on (and has always worked until sometime past week or longer)

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [November 13, 2024, 9:38am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/6 "2024-11-13T09:38:04Z")

</div>

I think we’ll need a new pair of eyes here because I’m out of ideas 🙃.  
Unless you are using some old Firefox?  
Or maybe you’ve misclicked a context menu on the toolbar icon?

 ![image](https://us1.discourse-cdn.com/flex001/uploads/mozilla/original/3X/1/5/154f5916e56ac3bbca99e45a12739f3a52bf756f.png)

---

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 9:40am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/7 "2024-11-13T09:40:47Z")

</div>

Wait it was checked like that by default? I’m on latest FF and just tried removing/re-installing and it defaults to “Only When Clicked” for me ☹

---

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 9:44am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/8 "2024-11-13T09:44:55Z")

</div>

I just changed to “Always Allow on [chatgpt.com](http://chatgpt.com)”, removed extension, then re-installed and it worked!!!

So if not a bug, it is at least undesirable that this context menu setting persists even when extensions are removed (it should stick w/ default behavior on fresh install) do you agree?

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [November 13, 2024, 9:46am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/9 "2024-11-13T09:46:42Z")

</div>

Note that the “true” re-installing requires restarting Firefox after uninstalling, otherwise data/settings are not really deleted when you install it back.

---

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 9:47am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/10 "2024-11-13T09:47:26Z")

</div>

Ok I trust you since I fear restarting FF since it takes forever to boot up previously open tabs, thank you for the solution!

---

<div class="post-metadata">

**Author:** ![adamlui](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/adamlui/32/66445_2.png) [@adamlui](https://discourse.mozilla.org/u/adamlui)\
**Post date:** [November 13, 2024, 9:48am UTC](https://discourse.mozilla.org/t/content-js-now-need-permissions-on-each-matching-url/137164/11 "2024-11-13T09:48:32Z")

</div>

![image](https://us1.discourse-cdn.com/flex001/uploads/mozilla/optimized/3X/c/8/c8a170ca65409637698026527e870bee08546fef_2_690x25.png)
