docs: 保存未暂存的图标/隐私政策/测试改动(shop ingest 用)
@@ -1,8 +1,19 @@
|
|||||||
# 隐私政策 / Privacy Policy
|
# 隐私政策 / Privacy Policy — Auto Login Manager
|
||||||
|
|
||||||
**Auto Login Manager**(下称"本扩展")
|
**扩展名称**:Auto Login Manager
|
||||||
|
**版本**:1.0.0
|
||||||
|
**生效日期**:2026-09-24
|
||||||
|
**政策最后更新**:2026-09-24
|
||||||
|
|
||||||
最后更新:2026-09-17
|
> 本文档用于 Chrome Web Store 上架隐私申报,与扩展仓库内 `PRIVACY.md` 口径一致。
|
||||||
|
> 联系方式已填写(见下方「8. 联系方式」)。发布前请将本政策正文托管到公网 URL(GitHub Pages / Gitee Pages / 自有站点均可),再把该 URL 填入 Developer Dashboard 的 Privacy 字段。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 目录
|
||||||
|
|
||||||
|
- [中文](#中文)
|
||||||
|
- [English](#english)
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -10,68 +21,82 @@
|
|||||||
|
|
||||||
### 一句话说明
|
### 一句话说明
|
||||||
|
|
||||||
本扩展**不收集、不存储、不上传**任何用户数据到任何服务器。所有数据仅保存在你自己的浏览器本机。
|
本扩展(Auto Login Manager)是一个浏览器端自动填充工具:你为特定网站保存登录配置(域名、用户名、密码),本扩展在你访问已授权网站时自动填充登录表单。**所有凭据仅在设置本机口令后以 AES-GCM-256 密文保存在你自己的浏览器本机;本扩展不包含任何网络请求代码,不将任何数据上传到任何服务器。**
|
||||||
|
|
||||||
### 1. 我们收集哪些数据
|
### 1. 我们收集哪些数据
|
||||||
|
|
||||||
**不收集任何数据。** 具体而言:
|
**我们只处理你主动录入的数据,并且这些数据不会离开你的设备。**
|
||||||
|
|
||||||
- 没有网络请求:本扩展不包含任何向外部服务器发送数据的代码
|
| 数据类型 | 是否收集 | 来源 | 用途 |
|
||||||
- 没有统计分析、没有崩溃上报、没有广告、没有第三方 SDK
|
| --- | --- | --- | --- |
|
||||||
- 不读取你的浏览历史(仅在你主动点击时读取当前标签页的地址与标题)
|
| 登录配置(域名/URL 匹配规则、用户名、密码、别名) | 是 | 你在扩展侧边栏手动录入,或通过「从书签导入」批量生成 | 核心功能:自动填充登录表单(单一用途) |
|
||||||
- 不收集设备标识、位置、联系人等任何信息
|
| 环境信息(环境名称、环境内配置分组) | 是 | 你创建环境时录入 | 多环境配置管理 |
|
||||||
|
| 设置项(自动提交、填充延迟、选择器、启用状态) | 是 | 你配置时录入 | 控制填充行为 |
|
||||||
|
| 自动提交失败计数 | 是 | 扩展运行产生 | 防止账号因连续自动提交被锁定(纯本地计数) |
|
||||||
|
| 浏览器书签 | 是(仅点击「从书签导入」时) | Chrome 书签 API | 仅在你主动触发时读取书签生成域名配置 |
|
||||||
|
|
||||||
|
**明确不收集**:
|
||||||
|
|
||||||
|
- 无网络请求:本扩展不含任何向外部服务器发送数据的代码(经代码审查确认,无 `fetch` / `XMLHttpRequest` / `WebSocket` / `sendBeacon` 调用)
|
||||||
|
- 无统计分析、无崩溃上报、无广告、无第三方 SDK
|
||||||
|
- 不读取浏览历史(未申请 `tabs` 权限;仅在你点击扩展图标时经 `activeTab` 临时访问当前标签页)
|
||||||
|
- 不收集设备标识、位置、联系人、支付信息
|
||||||
|
|
||||||
### 2. 数据保存在哪里
|
### 2. 数据保存在哪里
|
||||||
|
|
||||||
| 数据 | 位置 | 说明 |
|
| 数据 | 位置 | 说明 |
|
||||||
| --- | --- | --- |
|
| --- | --- | --- |
|
||||||
| 域名配置、用户名、密码、环境信息 | `chrome.storage.local` | 设置本机口令后以 **AES-GCM-256 密文**保存 |
|
| 域名配置、用户名、密码、环境信息 | `chrome.storage.local` | 设置本机口令后以 **AES-GCM-256 密文**保存 |
|
||||||
| 解锁期间的明文配置 | `chrome.storage.session` | 仅内存,浏览器关闭即清除 |
|
| 解锁期间的明文配置 | `chrome.storage.session` | 仅内存,浏览器关闭即清除;10 分钟无操作自动锁定 |
|
||||||
| 加密密钥句柄 | 扩展的 IndexedDB | 存的是**不可导出**的密钥对象(`extractable: false`),无法被读出原始密钥 |
|
| 加密密钥句柄 | 扩展专属 IndexedDB | 存的是**不可导出**的密钥对象(`extractable: false`),无法读出原始密钥字节 |
|
||||||
| 登录失败计数 | `chrome.storage.local` | 非敏感,仅用于失败次数限制 |
|
| 登录失败计数 | `chrome.storage.local` | 非敏感,仅用于失败次数限制 |
|
||||||
|
|
||||||
主口令本身**不会**被保存到任何位置。它仅用于派生加密密钥,解锁后只保留派生结果。
|
主口令本身**不会被保存**到任何存储位置。它仅用于派生加密密钥,解锁后只保留派生结果。
|
||||||
|
|
||||||
### 3. 加密方式
|
### 3. 加密方式
|
||||||
|
|
||||||
- 密钥派生:PBKDF2-SHA256,随机盐(本机口令 20 万次迭代;导出文件的口令 10 万次迭代)
|
- 密钥派生:PBKDF2-SHA256 + 随机盐(本机口令 **200,000** 次迭代;导出文件口令 100,000 次迭代)
|
||||||
- 数据加密:AES-GCM-256(带完整性校验的认证加密)
|
- 数据加密:AES-GCM-256(带完整性校验的认证加密)
|
||||||
- 密钥属性:不可导出(`exportKey()` 会失败),只能用于加解密
|
- 密钥属性:不可导出(`exportKey()` 按设计失败),只能用于加解密
|
||||||
|
|
||||||
如果你忘记本机口令,**数据无法恢复**,这是加密设计的必然结果。
|
如果你忘记本机口令,**数据无法恢复**,这是加密设计的必然结果。
|
||||||
|
|
||||||
### 4. 权限用途
|
### 4. 权限用途(与清单权限逐项对应)
|
||||||
|
|
||||||
本扩展申请以下权限,用途均限于实现自动填充功能:
|
本扩展在 `manifest.json` 中声明以下权限,每一项都有真实用途:
|
||||||
|
|
||||||
- `storage`:保存配置与解锁期间的会话数据
|
| 权限 | 用途 |
|
||||||
- `activeTab`:你点击扩展图标时**临时**访问当前标签页,用于「在当前页面填充」与「填入当前域名」
|
| --- | --- |
|
||||||
- `scripting`:在需要时注入填充脚本
|
| `storage` | 保存加密配置(`storage.local`)与解锁期间的会话数据(`storage.session`) |
|
||||||
- `sidePanel`:显示侧边栏界面
|
| `activeTab` | 你点击扩展图标时**临时**访问当前标签页,用于「在当前页面填充」与「填入当前域名」 |
|
||||||
- `bookmarks`:仅在你点击「从书签导入」时读取书签,用于批量生成域名配置
|
| `scripting` | 在需要时按需注入填充脚本 |
|
||||||
- 网站访问权限(`optional_host_permissions`):本扩展**不声明**安装时生效的全站访问权限。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;**未授权的网站不会执行任何本扩展脚本**。你可以随时在 `chrome://extensions` 中撤销这些授权,撤销后该网站不再自动填充(手动填充仍可用)
|
| `sidePanel` | 显示扩展侧边栏界面 |
|
||||||
|
| `bookmarks` | 仅当你点击「从书签导入」时读取书签,用于批量生成域名配置 |
|
||||||
|
|
||||||
在你已授权的网站内,脚本会注入到该页面的所有框架(含 iframe),以便填充内嵌在 iframe 中的登录表单(如 SSO 登录页)。每个框架都会用自己的地址去匹配你配置的域名,**不匹配的框架不会做任何填充操作**。
|
**网站访问权限采取最小化设计**:本扩展未在安装时申请任何全站访问权限(manifest 仅含 `optional_host_permissions: ["*://*/*"]`)。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;**未授权的网站不会执行任何本扩展脚本**。你可以随时在 `chrome://extensions` 中撤销授权,撤销后该网站不再自动填充(手动填充仍可用)。
|
||||||
|
|
||||||
本扩展未声明 `tabs` 权限,因此不会读取你的浏览记录。
|
**无强制内容注入**:本扩展的 manifest 中不包含 `content_scripts` 声明,不会在你未授权的情况下自动向任何网页注入脚本;填充脚本仅在已授权网站或你手动触发时按需注入。
|
||||||
|
|
||||||
### 5. 数据的导出与删除
|
### 5. 数据的导出与删除
|
||||||
|
|
||||||
- **导出**:由你主动触发,导出的文件保存在你指定的位置,可选择用文件口令加密
|
- **导出**:由你主动触发,导出的文件保存在你指定的位置,可选择用文件口令加密后导出
|
||||||
- **删除单条配置**:在侧边栏中删除即可
|
- **删除单条配置**:在侧边栏中删除即可
|
||||||
- **删除全部数据**:卸载本扩展,或在浏览器中清除该扩展的存储数据
|
- **删除全部数据**:卸载本扩展,或清除该扩展的存储数据(`chrome://extensions` → 扩展详情 → 清除数据)
|
||||||
|
|
||||||
### 6. 第三方共享
|
### 6. 第三方共享
|
||||||
|
|
||||||
不存在。本扩展不与任何第三方共享数据,因为它根本不向外传输数据。
|
不存在。本扩展不与任何第三方共享数据,因为它不向外传输数据;不涉及数据出售、广告、跨站追踪。
|
||||||
|
|
||||||
### 7. 政策变更
|
### 7. 政策变更
|
||||||
|
|
||||||
若本政策发生实质性变更,将在本文件顶部的"最后更新"日期中体现,并随扩展版本更新一并发布。
|
若本政策发生实质性变更,将更新本文件顶部的「政策最后更新」日期,并随扩展版本更新一并发布;涉及数据处理方式变更时,将按 Chrome Web Store 政策要求主动进行显著披露。
|
||||||
|
|
||||||
### 8. 联系方式
|
### 8. 联系方式
|
||||||
|
|
||||||
如有疑问,请在本项目仓库提交 Issue。
|
- 支持 / 反馈:**chenxuanvictory@163.com**
|
||||||
|
- 项目主页:**http://218.61.196.156:41695/Chrome-extension/auto-login.git**
|
||||||
|
|
||||||
|
如有隐私相关问题,也可通过上述渠道联系我们,我们会在合理时间内回复。
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -79,54 +104,77 @@
|
|||||||
|
|
||||||
### Summary
|
### Summary
|
||||||
|
|
||||||
This extension **does not collect, store, or transmit** any user data. Everything stays in your own browser on your own machine.
|
Auto Login Manager is a browser-side auto-fill tool. You save login entries (domain, username, password) for websites you choose; the extension auto-fills the login form when you visit an authorized site. **All credentials are stored on your own machine, encrypted with AES-GCM-256 after you set a local master password. The extension contains no networking code and transmits nothing anywhere.**
|
||||||
|
|
||||||
### Data We Collect
|
### 1. Data We Collect
|
||||||
|
|
||||||
**None.** There are no network requests, no analytics, no crash reporting, no ads, and no third-party SDKs.
|
**We only handle data you enter yourself, and it never leaves your device.**
|
||||||
|
|
||||||
### Where Data Is Stored
|
| Data type | Collected | Source | Purpose |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| Login entries (domain / URL match rules, username, password, alias) | Yes | You type them into the side panel, or generate them in bulk via "import from bookmarks" | Core function: auto-fill login forms (single purpose) |
|
||||||
|
| Environment info (environment names and config groups) | Yes | You create environments in the UI | Multi-environment config management |
|
||||||
|
| Settings (auto-submit, fill delay, selectors, enabled state) | Yes | You configure them | Control fill behavior |
|
||||||
|
| Auto-submit failure counters | Yes | Generated by the extension at runtime | Prevents account lockout from repeated auto-submits (local counter only) |
|
||||||
|
| Browser bookmarks | Yes (only when you click "import from bookmarks") | Chrome bookmarks API | Read bookmarks only when you explicitly trigger the import |
|
||||||
|
|
||||||
|
**Explicitly not collected**:
|
||||||
|
|
||||||
|
- No network requests: the extension contains no code that sends data to any server (verified by code review: no `fetch` / `XMLHttpRequest` / `WebSocket` / `sendBeacon` calls)
|
||||||
|
- No analytics, no crash reporting, no ads, no third-party SDKs
|
||||||
|
- No browsing history (the `tabs` permission is not requested; the active tab is accessed temporarily via `activeTab` only when you click the extension icon)
|
||||||
|
- No device identifiers, location, contacts, or payment information
|
||||||
|
|
||||||
|
### 2. Where Data Is Stored
|
||||||
|
|
||||||
| Data | Location | Notes |
|
| Data | Location | Notes |
|
||||||
| --- | --- | --- |
|
| --- | --- | --- |
|
||||||
| Domain configs, usernames, passwords, environments | `chrome.storage.local` | Stored as **AES-GCM-256 ciphertext** once a master password is set |
|
| Domain configs, usernames, passwords, environments | `chrome.storage.local` | Stored as **AES-GCM-256 ciphertext** once a master password is set |
|
||||||
| Decrypted configs while unlocked | `chrome.storage.session` | In-memory only, cleared when the browser closes |
|
| Decrypted configs while unlocked | `chrome.storage.session` | In-memory only; cleared when the browser closes; auto-locks after 10 minutes of inactivity |
|
||||||
| Encryption key handle | Extension IndexedDB | A **non-extractable** key object; the raw key bytes cannot be read out |
|
| Encryption key handle | Extension-owned IndexedDB | A **non-extractable** key object; raw key bytes cannot be read out |
|
||||||
| Login failure counters | `chrome.storage.local` | Non-sensitive, used to throttle repeated auto-submits |
|
| Login failure counters | `chrome.storage.local` | Non-sensitive; used only to throttle repeated auto-submits |
|
||||||
|
|
||||||
The master password itself is **never** written to any storage. It is only used to derive the encryption key.
|
The master password itself is **never written to any storage**. It is only used to derive the encryption key.
|
||||||
|
|
||||||
### Encryption
|
### 3. Encryption
|
||||||
|
|
||||||
- Key derivation: PBKDF2-SHA256 with a random salt (200,000 iterations for the master password; 100,000 for exported file passwords)
|
- Key derivation: PBKDF2-SHA256 with a random salt (200,000 iterations for the master password; 100,000 for exported file passwords)
|
||||||
- Encryption: AES-GCM-256 (authenticated encryption)
|
- Data encryption: AES-GCM-256 (authenticated encryption with integrity checks)
|
||||||
- Key property: non-extractable — `exportKey()` fails by design
|
- Key property: non-extractable — `exportKey()` fails by design
|
||||||
|
|
||||||
If you forget your master password, the data **cannot be recovered**. That is an inherent property of the encryption design.
|
If you forget your master password, the data **cannot be recovered**. That is an inherent property of the encryption design.
|
||||||
|
|
||||||
### Permissions
|
### 4. Permissions (mapped 1:1 to the declared permissions)
|
||||||
|
|
||||||
- `storage` — save configs and unlocked session data
|
| Permission | Purpose |
|
||||||
- `activeTab` — **temporary** access to the active tab when you click the extension icon, used for "fill current page" and "fill current domain"
|
| --- | --- |
|
||||||
- `scripting` — inject the fill script on demand
|
| `storage` | Save encrypted configs (`storage.local`) and unlocked session data (`storage.session`) |
|
||||||
- `sidePanel` — render the side panel UI
|
| `activeTab` | **Temporary** access to the active tab when you click the extension icon, for "fill current page" and "fill current domain" |
|
||||||
- `bookmarks` — read bookmarks only when you click "import from bookmarks"
|
| `scripting` | Inject the fill script on demand |
|
||||||
- Site access (`optional_host_permissions`) — this extension does **not** request install-time access to all websites. You are asked once, when you save a config for a domain, whether to allow access to that site. **No script runs on sites you have not authorized.** You can revoke these grants at any time from `chrome://extensions`; revoked sites simply stop auto-filling (manual fill still works).
|
| `sidePanel` | Render the side panel UI |
|
||||||
|
| `bookmarks` | Read bookmarks only when you click "import from bookmarks", to generate domain configs in bulk |
|
||||||
|
|
||||||
On sites you have authorized, the script is injected into every frame of the page (including iframes) so that login forms embedded in an iframe (such as SSO pages) can be filled. Each frame matches your configured domains against its own URL; **frames that do not match perform no filling at all**.
|
**Site access is minimal by design**: the extension does not request any install-time access to all websites (the manifest only declares `optional_host_permissions: ["*://*/*"]`). You are asked once, when you save a config for a domain, whether to allow access to that site. **No extension script runs on sites you have not authorized.** You can revoke grants at any time from `chrome://extensions`; revoked sites simply stop auto-filling (manual fill still works).
|
||||||
|
|
||||||
The `tabs` permission is not requested, so your browsing history is not read.
|
**No forced content injection**: the manifest declares no `content_scripts`. The extension never injects scripts into any page without your authorization; fill scripts are injected on demand only on authorized sites or when you trigger fill manually.
|
||||||
|
|
||||||
### Export and Deletion
|
### 5. Export and Deletion
|
||||||
|
|
||||||
- Export is always user-initiated; optional file-password encryption is available
|
- Export is always user-initiated; optional file-password encryption is available
|
||||||
- Delete individual entries in the side panel
|
- Delete individual entries in the side panel
|
||||||
- Delete everything by uninstalling the extension or clearing its storage data
|
- Delete everything by uninstalling the extension or clearing its storage data
|
||||||
|
|
||||||
### Third Parties
|
### 6. Third Parties
|
||||||
|
|
||||||
None. The extension does not transmit data anywhere.
|
None. The extension does not share data with any third party because it does not transmit data anywhere; no data selling, no ads, no cross-site tracking.
|
||||||
|
|
||||||
### Contact
|
### 7. Policy Changes
|
||||||
|
|
||||||
Please open an issue in this project's repository.
|
Material changes will be reflected in the "Last updated" date at the top of this document and shipped with a new extension version. Changes to data handling practices will be proactively disclosed as required by Chrome Web Store policy.
|
||||||
|
|
||||||
|
### 8. Contact
|
||||||
|
|
||||||
|
- Support / feedback: **chenxuanvictory@163.com**
|
||||||
|
- Project home: **http://218.61.196.156:41695/Chrome-extension/auto-login.git**
|
||||||
|
|
||||||
|
For privacy-related questions, please contact us through the channels above; we will respond within a reasonable timeframe.
|
||||||
@@ -1 +1,6 @@
|
|||||||
<?xml version="1.0" standalone="no"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg class="icon" width="200px" height="200px" viewBox="248 248 528 528" version="1.1" xmlns="http://www.w3.org/2000/svg"><path fill="#e6e6e6" d="M531 732.213c109.663-9.128 197.085-96.55 206.213-206.213H699c-9.389 0-17-7.611-17-17s7.611-17 17-17h38.51C730.203 380.467 641.995 291.025 531 281.787V316c0 9.389-7.611 17-17 17s-17-7.611-17-17v-34.51C384.134 288.885 293.885 379.132 286.49 492H325c9.389 0 17 7.611 17 17s-7.611 17-17 17h-38.212c3.376 40.555 17.521 78.913 40.845 111.74 5.438 7.653 3.642 18.266-4.012 23.704-7.653 5.438-18.266 3.642-23.704-4.012C268.924 613.812 252 561.651 252 507c0-143.597 116.405-260 260-260 0.531 0 1.062 0.002 1.593 0.005a17.327 17.327 0 0 1 1.093 0.009C657.048 248.454 772 364.297 772 507c0 142.699-114.954 258.546-257.314 259.986a17.298 17.298 0 0 1-1.093 0.01c-0.53 0.002-1.062 0.004-1.593 0.004-35.196 0-69.447-7.01-101.207-20.439-8.648-3.656-12.694-13.63-9.038-22.278 3.656-8.648 13.63-12.694 22.278-9.038 23.063 9.752 47.636 15.606 72.967 17.265V698c0-9.389 7.611-17 17-17s17 7.611 17 17v34.213z m16.86-189.408a16.988 16.988 0 0 1-4.05 3.412l-121 73.322c-15.204 9.213-32.562-8.145-23.349-23.35l73.322-121a16.99 16.99 0 0 1 3.353-3.997 17.034 17.034 0 0 1 4.054-3.41l121-73.321c15.204-9.213 32.562 8.146 23.349 23.35l-50.267 82.946c-4.866 8.03-15.32 10.594-23.35 5.728-8.029-4.866-10.593-15.32-5.727-23.349l14.354-23.687-43.202 26.179 32.35 32.351c6.639 6.64 6.639 17.403 0 24.042-0.273 0.272-0.552 0.534-0.838 0.784z m-38.118-15.699l-17.848-17.848-27.448 45.296 45.296-27.448z" /></svg>
|
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 16 16" width="16" height="16">
|
||||||
|
<rect x="0.5" y="0.5" width="15" height="15" rx="3" fill="none" stroke="#e94560" stroke-opacity="0.6" stroke-width="1.5"/>
|
||||||
|
<circle cx="8" cy="8" r="3.5" fill="none" stroke="#e94560" stroke-opacity="0.7" stroke-width="1.5"/>
|
||||||
|
<path d="M4.5 8h7M8 4.5v7" stroke="#e94560" stroke-opacity="0.6" stroke-width="1.5" stroke-linecap="round"/>
|
||||||
|
<circle cx="8" cy="8" r="1" fill="#e94560" fill-opacity="0.7"/>
|
||||||
|
</svg>
|
||||||
|
Before Width: | Height: | Size: 1.6 KiB After Width: | Height: | Size: 495 B |
|
Before Width: | Height: | Size: 5.3 KiB After Width: | Height: | Size: 5.5 KiB |
|
Before Width: | Height: | Size: 631 B After Width: | Height: | Size: 652 B |
|
Before Width: | Height: | Size: 2.4 KiB After Width: | Height: | Size: 2.4 KiB |
@@ -119,9 +119,12 @@ function loadContentPage({
|
|||||||
timing,
|
timing,
|
||||||
setup,
|
setup,
|
||||||
} = {}) {
|
} = {}) {
|
||||||
|
// pretendToBeVisual: 让 jsdom 提供 requestAnimationFrame(content.js 的填充完成 toast 依赖它),
|
||||||
|
// 否则 showFillToast() 会抛 ReferenceError。
|
||||||
const dom = new JSDOM(`<!DOCTYPE html><html><body>${html}</body></html>`, {
|
const dom = new JSDOM(`<!DOCTYPE html><html><body>${html}</body></html>`, {
|
||||||
url,
|
url,
|
||||||
runScripts: "dangerously",
|
runScripts: "dangerously",
|
||||||
|
pretendToBeVisual: true,
|
||||||
});
|
});
|
||||||
const win = dom.window;
|
const win = dom.window;
|
||||||
|
|
||||||
|
|||||||