Como corrigir erro de invocação de JavaScript embutido chrome-extension?

Estou fazendo uma extensão do Chrome, no entanto, parece que recebo o seguinte erro ao tentar iniciar um evento onclick ().

Refused to load the script '' because it violates the following Content Security Policy directive: "script-src 'self' blob: filesystem: chrome-extension-resource:"


Refused to execute inline event handler because it violates the following Content Security Policy directive: "script-src 'self' blob: filesystem: chrome-extension-resource:". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution.

Este é o meu manifest.json:

  "manifest_version": 2,

  "name": "SECURE",
  "description": "this extension offers secure communication for GMAIL     users",
  "version": "1.0",

 "browser_action": {
 "default_icon": "resources/icon16.png",
 "default_popup": "popup.html",
 "default_title": "Click here!"



 "content_scripts": [
   "matches": ["http://*/*", "https://*/*"],
   "run_at": "document_end"
"permissions": ["identity", "*",  "*"],

"oauth2": {
   "client_id": "",
 "scopes": [
   "<all urls>",

 "content_security_policy":"script-src 'self'  'unsafe-inline' 'unsafe eval'; object-src 'self'"


Qualquer ajuda para corrigir esse erro seria muito apreciada.

