To the extent possible under law, the editors have waived all copyright
and related or neighboring rights to this work.
In addition, as of 4 September 2026,
the editors have made this specification available under the
Open Web Foundation Agreement Version 1.0,
which is available at https://www.openwebfoundation.org/the-agreements/the-owf-1-0-agreements-granted-claims/owfa-1-0.
Parts of this work may be from another specification document. If so, those parts are instead covered by the license of that specification document.
Abstract
This specification defines globs, the wildcard syntax used by the include_globs and exclude_globs content script keys, and the algorithm for matching a URL against one.
1. Globs
A glob is a string matched against a URL. It may
contain the wildcard characters *, which matches zero or
more characters, and ?. Every character other than a wildcard
matches only itself, so a glob with no wildcards matches only a URL
identical to it.
Glob matching is case-sensitive.
Does a single ? match exactly one character, or zero or one? The
published specification
says exactly one, and Firefox matches that. In Chrome a run of k
consecutive ? matches 0 to k characters, so a lone ? can match zero.
Should \ escape the next * or ? in a glob, as in Chrome, or have no special meaning, as
in Firefox?
Chrome treats \ as an escape character for the next * or ?. Firefox has no escape syntax:
a \ in a glob is matched as a literal backslash, and there is no way to write a literal *
or ?.
Should a glob be matched against the full URL, or the URL without its fragment?
Chrome includes the fragment. Firefox strips it, so a glob ending in
#section matches in Chrome and never in Firefox.
Given the URL https://example.com/path?query#frag:
*example.com* matches in both Chrome and Firefox.
*#frag matches in Chrome, but not in Firefox, because Firefox matches against the URL with its fragment removed.
1.1. Key include_globs
A list of globs. A document matches if the URL matches both the matches field and the include_globs field. If include_globs is empty or not present, it does not restrict matching.
Should an empty include_globs list restrict nothing, or match nothing?
Chrome treats it as no restriction, and so does Firefox’s userScripts API. Firefox’s
content_scripts manifest key does not: there an empty list matches nothing.
1.2. Key exclude_globs
A list of globs used to specify URLs where the content script does not run, even if the URL matches entries in matches and (if specified) § 1.1 Key include_globs. If exclude_globs is empty or not present, it does not exclude anything.
Conformance
Conformance requirements are expressed with a combination of descriptive assertions and RFC 2119 terminology.
The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “MAY”, and “OPTIONAL”
in the normative parts of this document
are to be interpreted as described in RFC 2119.
However, for readability,
these words do not appear in all uppercase letters in this specification.
All of the text of this specification is normative
except sections explicitly marked as non-normative, examples, and notes. [RFC2119]
Examples in this specification are introduced with the words “for example”
or are set apart from the normative text with class="example", like this:
This is an example of an informative example.
Informative notes begin with the word “Note”
and are set apart from the normative text with class="note", like this:
Does a single ? match exactly one character, or zero or one? The
published specification
says exactly one, and Firefox matches that. In Chrome a run of k
consecutive ? matches 0 to k characters, so a lone ? can match zero. ↵
Should \ escape the next * or ? in a glob, as in Chrome, or have no special meaning, as
in Firefox?
Chrome treats \ as an escape character for the next * or ?. Firefox has no escape syntax:
a \ in a glob is matched as a literal backslash, and there is no way to write a literal *
or ?.
Should an empty include_globs list restrict nothing, or match nothing?
Chrome treats it as no restriction, and so does Firefox’s userScripts API. Firefox’s
content_scripts manifest key does not: there an empty list matches nothing.