In Public Sessions, apps and extensions are force-installed by admin policy so the user does not get a chance to review the permissions for these apps. This is not acceptable from a security standpoint, so we scrub the URL returned by chrome.tabs API down to the origin.
Summary: Public Session whitelisting - Scrub URL return by chrome.tabs down to origin (was: Public Session whitelisting - Scrub URL down to origin in Public Sessions)
Comment 1 by isandrk@chromium.org
, Apr 21 2017