01 / CSP
The host application's content-security policy restricts how extension code can execute and communicate.
Case study
Integrations
A Chrome extension that writes reconciled transactions into a legacy ERP through CSP restrictions, nested frames, and asynchronous batch workflows.
Outcome
Reliable write-back into a critical system with no suitable API.
Constraint
Yardi Voyager is the accounting system of record, but the available integration surface could not complete this workflow. The extension had to operate through the authenticated browser UI, recover from partial batches, and preserve a manual path when OCR was uncertain.
Hostile integration surface
01 / CSP
The host application's content-security policy restricts how extension code can execute and communicate.
02 / Frames
Critical grids live inside nested frames, so the integration must find the right document before it can act.
03 / Batches
Invoice assignment completes asynchronously; success means observing the final batch state, not just clicking submit.
04 / Recovery
Duplicate numbers, orphaned batches, and partial failures must remain inspectable and safe to resume.
Fallback chain
01
Prefer a machine-readable identifier when the receipt provides one.
02
Extract and match invoice evidence when no reliable barcode exists.
03
Stop and expose the fields when evidence conflicts or remains incomplete.
Engineering decision
UI automation is reliable only when each action has a verifiable postcondition. The extension polls batch state, checks the assigned records, and leaves failed items recoverable instead of treating a successful DOM event as completion.
This accounting extension is separate from the published maintenance extension. See the broaderexpense reconciliation case study →
3
Fallback Stages
MV3
Chrome Extension
CSP
Constrained Runtime
Fail Closed
Ambiguous Matches
Built With