feat: 按域名授权、iframe 多帧填充、自动提交限流修正,并补齐工程规范与文档
安全与权限: - 站点访问权限改为 optional_host_permissions,保存配置时逐域名授权;移除 host_permissions 与 tabs,安装提示不再出现全站数据访问与浏览记录 - 主口令不再写入 storage.session,改用 IndexedDB 中不可导出的 CryptoKey 句柄恢复解锁,锁定即丢弃 - content script 注入范围只注册已授权域名,并随权限变化即时收敛 自动登录: - 支持 iframe 内的登录表单:脚本注入所有帧,逐帧按自身地址匹配配置 - 手动填充改为逐帧探测,定向发送到真正含密码框的帧 - 限流修正:只在真正触发提交后计数;判定登录成功后立即清零;达到上限时页面给出可见提示;重置判断只看启用中的配置 - SPA 重试改为 DOM 变更门控 + 退避,并单独监听已发现的 Shadow Root 工程化与文档: - 引入 ESLint(扁平配置)与 Prettier,CI 增加 lint 与 format:check - 信息类日志改为 debugLog(默认静默,chrome.storage.local.debugLog 开关) - 测试 123 → 128 用例(新增权限、iframe、限流相关用例) - README / PRIVACY / CHANGELOG 同步
This commit is contained in:
+12
-6
@@ -45,12 +45,15 @@
|
||||
本扩展申请以下权限,用途均限于实现自动填充功能:
|
||||
|
||||
- `storage`:保存配置与解锁期间的会话数据
|
||||
- `tabs`:读取当前标签页地址 / 标题,用于「填入当前域名」与登录页匹配
|
||||
- `activeTab`:你点击扩展图标时**临时**访问当前标签页,用于「在当前页面填充」与「填入当前域名」
|
||||
- `scripting`:在需要时注入填充脚本
|
||||
- `activeTab`:你点击扩展时临时访问当前标签页
|
||||
- `sidePanel`:显示侧边栏界面
|
||||
- `bookmarks`:仅在你点击「从书签导入」时读取书签,用于批量生成域名配置
|
||||
- 访问所有网站的权限(`<all_urls>`):因为你可以为任意域名配置自动登录;**实际注入范围严格限定为你配置过的域名**,未配置的网站不会执行任何本扩展脚本
|
||||
- 网站访问权限(`optional_host_permissions`):本扩展**不声明**安装时生效的全站访问权限。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;**未授权的网站不会执行任何本扩展脚本**。你可以随时在 `chrome://extensions` 中撤销这些授权,撤销后该网站不再自动填充(手动填充仍可用)
|
||||
|
||||
在你已授权的网站内,脚本会注入到该页面的所有框架(含 iframe),以便填充内嵌在 iframe 中的登录表单(如 SSO 登录页)。每个框架都会用自己的地址去匹配你配置的域名,**不匹配的框架不会做任何填充操作**。
|
||||
|
||||
本扩展未声明 `tabs` 权限,因此不会读取你的浏览记录。
|
||||
|
||||
### 5. 数据的导出与删除
|
||||
|
||||
@@ -104,12 +107,15 @@ If you forget your master password, the data **cannot be recovered**. That is an
|
||||
### Permissions
|
||||
|
||||
- `storage` — save configs and unlocked session data
|
||||
- `tabs` — read the active tab's URL/title for "fill current domain" and login-page matching
|
||||
- `activeTab` — **temporary** access to the active tab when you click the extension icon, used for "fill current page" and "fill current domain"
|
||||
- `scripting` — inject the fill script on demand
|
||||
- `activeTab` — temporary access to the active tab when you click the extension
|
||||
- `sidePanel` — render the side panel UI
|
||||
- `bookmarks` — read bookmarks only when you click "import from bookmarks"
|
||||
- `<all_urls>` — you may configure auto-login for any domain; the **actual injection scope is limited to domains you configured**. No script runs on unconfigured sites.
|
||||
- Site access (`optional_host_permissions`) — this extension does **not** request install-time access to all websites. You are asked once, when you save a config for a domain, whether to allow access to that site. **No script runs on sites you have not authorized.** You can revoke these grants at any time from `chrome://extensions`; revoked sites simply stop auto-filling (manual fill still works).
|
||||
|
||||
On sites you have authorized, the script is injected into every frame of the page (including iframes) so that login forms embedded in an iframe (such as SSO pages) can be filled. Each frame matches your configured domains against its own URL; **frames that do not match perform no filling at all**.
|
||||
|
||||
The `tabs` permission is not requested, so your browsing history is not read.
|
||||
|
||||
### Export and Deletion
|
||||
|
||||
|
||||
Reference in New Issue
Block a user