diff --git a/cws-store/01-上架材料核对表.md b/cws-store/01-上架材料核对表.md
new file mode 100644
index 0000000..ed2259a
--- /dev/null
+++ b/cws-store/01-上架材料核对表.md
@@ -0,0 +1,189 @@
+# Auto Login Manager — Chrome Web Store 上架材料核对表
+
+> 适用范围:Manifest V3 扩展「Auto Login Manager」v1.0.0
+> 核对依据:Chrome Web Store 官方文档(Program Policies / Privacy / Listing Requirements / Supplying Images / Publish / Register,镜像域 developer.chrome.google.cn)与仓库实际代码审查
+> 生成时间:2026-09-24
+> 状态图例:✔ 已就绪(随本套材料交付)|⏳ 需你在控制台/外部平台完成|– 不适用或可选
+
+---
+
+## 0. 一键速览(TL;DR)
+
+| 环节 | 需要什么 | 状态 |
+| --- | --- | --- |
+| 开发者账号 | 一次性 $5 注册费 + 开启两步验证(2FA) | ✔ 已开 2FA,已支付 $5 注册费(2026-09-24 确认) |
+| 扩展包 | `auto-login-v1.0.0.zip`(≤2GB,MV3,无远程代码) | ✔ 见第 2 节 |
+| 商店图标 | 128x128 PNG(图形约占 96x96,留透明边) | ✔ `icons/icon128.png`(已像素实测:图形 96x96 居中 + 四周各 16px 透明边距,合规) |
+| 截图 | ≥1 张,最多 5 张,1280x800 或 640x400 | ⏳ 需你截屏(见第 4 节规格说明) |
+| 促销图 | 440x280 小促销图(必填);1400x560 Marquee(可选) | ✔ `cws-store/promo/`(英文版已生成,实测尺寸精确) |
+| 商店描述 | 中英双语(本扩展默认 zh_CN + en,需逐语言填写) | ✔ 见第 5 节 |
+| 隐私字段 | 单一用途描述、逐权限理由、远程代码声明、数据使用申报、隐私政策 URL | ✔ 文案见第 6 节 + `cws-store/privacy.html`(URL 待 push,见 `URL-填写清单.md`) |
+| 分发设置 | 地区(默认全部)、付费与否(免费)、可见范围 | ⏳ 控制台选择 |
+| 提交审核 | Dashboard → Submit for Review;可选延迟发布 | ⏳ 你操作 |
+
+**提交前仍需你完成的外部事项**:① 把 `cws-store/privacy.html` push 到远程 `master` 并确认仓库对匿名访客可读,再把 raw URL 填入隐私字段(三处 URL 可填值与前置核对详见 `URL-填写清单.md`;`218.61.196.156:41695` 已确认公网可达、仅 http);② 完成 3–5 张 1280x800 真机截图。促销图与隐私政策页面均已生成。
+
+---
+
+## 1. 开发者账号与注册
+
+| # | 材料/要求 | 说明 | 状态 |
+| --- | --- | --- | --- |
+| 1.1 | Google 开发者账号 | 用户已准备 | ✔ |
+| 1.2 | 一次性注册费 $5 | 注册开发者账号时支付一次,非年费、非按扩展收费 | ⏳ 注册时支付 |
+| 1.3 | 两步验证(2FA) | 2024 年起发布/更新扩展必须开启 Google 账号两步验证 | ⏳ 确认已开启 |
+| 1.4 | 账号启用后初始发布上限 | 新账号默认最多 2 个**已发布**扩展;达到上限可在 Dashboard 申请提升 | – 首个扩展不受影响 |
+
+---
+
+## 2. 扩展包(上传的 zip)
+
+| # | 材料/要求 | 说明 | 状态 |
+| --- | --- | --- | --- |
+| 2.1 | 可上传的 zip 包 | `release/auto-login-v1.0.0.zip`(构建脚本只收运行时文件:manifest.json、popup.html、popup.css、icons、\_locales、dist) | ✔ 见第 7 节 |
+| 2.2 | Manifest V3 | `manifest_version: 3`,service worker 后台 | ✔ |
+| 2.3 | 无远程代码 | 代码审查:无 `eval`/`new Function`/动态远程脚本加载;全部逻辑随包分发 | ✔ |
+| 2.4 | 权限最小化 | 5 项权限均有真实用途(见第 6.2 节逐项理由),无冗余 `tabs` 等权限 | ✔ |
+| 2.5 | 无内容脚本强制注入 | manifest 无 `content_scripts` 声明;脚本仅在用户保存配置并授权站点后、或手动点击填充时按需注入(`scripting` API) | ✔ |
+| 2.6 | 站点访问最小化 | 主机权限为 `optional_host_permissions: ["*://*/*"]`,安装时不申请全站访问;按域名逐一授权,拒绝授权仅影响该站自动填充,手动填充仍可用 | ✔ |
+| 2.7 | 压缩包大小 | ≤2GB | ✔(实际远小于此) |
+| 2.8 | 包内不加源码/测试/部署文件 | 打包脚本已排除 src、tests、scripts、updates.xml、install-policy.reg、README 等 | ✔ |
+| 2.9 | zip 内路径用正斜杠、无嵌套单目录 | 打包脚本已处理 | ✔ |
+
+---
+
+## 3. Store Listing(商店列表)字段
+
+| # | 字段 | 要求/上限 | 本扩展填写 | 状态 |
+| --- | --- | --- | --- | --- |
+| 3.1 | 扩展名称 | 控制台名称字段(建议简短,≤75 字符内) | **Auto Login Manager** | ✔ |
+| 3.2 | 详细描述 | 无硬性字数上限但禁关键词堆砌(同一词反复出现 ≥5 次可能被判 spam);开头一句话说明功能 | 中英双语,见第 5 节 | ✔ |
+| 3.3 | 主分类(Category) | 单选;正确分类影响搜索 | **Productivity**(生产力) | ✔ 建议 |
+| 3.4 | 语言(Language) | 每支持一种 \_locales 语言可填一套描述/截图/视频 | zh-CN + en(已有 `_locales/zh_CN`、`_locales/en`) | ✔ |
+| 3.5 | 商店图标 | 128x128 PNG;图形约占 96x96、四周 ≥16px 透明;浅深色背景均清晰 | `icons/icon128.png`(像素实测:图形占 96x96 居中,四周各 16px 透明边距,完全符合要求,无需重制;icon16/icon48 为运行时工具栏/菜单图标,非商店图表,满布属正常,不受此规则约束) | ✔ |
+| 3.6 | 截图 | **至少 1 张**,最多 5 张;1280x800 或 640x400;直角无边框(full bleed) | 待截屏(规格见第 4 节) | ⏳ |
+| 3.7 | 小促销图 Small promo tile | **440x280 PNG/JPEG,必填**;少图/缺图会排在带图扩展之后 | `cws-store/promo/promo-440x280.png`(英文版,已按规格生成、实测尺寸精确) | ✔ |
+| 3.8 | 大促销图 Marquee promo tile | 1400x560 PNG/JPEG,可选;提供才可能上首页推荐位 | `cws-store/promo/promo-1400x560.png`(英文版,已按规格生成、实测尺寸精确) | ✔ |
+| 3.9 | 宣传视频 YouTube 链接 | 官方列表页提及;Supplying Images 页确认非强制 | 可不提供 | – 可选 |
+| 3.10 | 主页 URL(Official URL / Homepage) | 展示在详情页;验证归属后可显示"已验证发布者"角标 | **`http://218.61.196.156:41695/Chrome-extension/auto-login`**(Gitea 仓库 Web 首页,已确认公网可达) | ✔ |
+| 3.11 | 支持 URL(Support URL) | 用户帮助/反馈入口 | **`http://218.61.196.156:41695/Chrome-extension/auto-login`**(Gitea 仓库页,含 Issues 入口) | ✔ |
+| 3.12 | 内容分级(Mature content) | 默认不勾选;本扩展无成人内容 | 不勾选 | ✔ |
+| 3.13 | 多语言一致性 | 各语言描述不能显著改变功能描述(控制台自动比对,warning 可忽略但建议一致) | 中英文案已对齐口径 | ✔ |
+
+---
+
+## 4. 图片规格速查(详细指引见配套文档「截图与宣传图规格说明」)
+
+| 图片 | 尺寸 | 格式 | 必填 | 要点 |
+| --- | --- | --- | --- | --- |
+| 商店图标 | 128x128 | PNG | ✔ | 图形占 96x96 中心,四周透明边;无描边;浅深色背景都清晰 |
+| 截图 | 1280x800(首选)或 640x400 | PNG/JPEG | ✔ ≥1,最多 5 | 直角、无圆角/无边框/无 padding;展示真实界面;数字不小(下采样到 640x400 展示) |
+| 小促销图 | 440x280 | PNG/JPEG | ✔ | 少用文字;半尺寸仍可读;深饱和色;填满整幅 |
+| Marquee 促销图 | 1400x560 | PNG/JPEG | 可选 | 同上 |
+
+---
+
+## 5. 商店列表文案(可直接粘贴)
+
+详见配套文档「商店列表材料(中英双语)」:名称、一句话简介、详细描述、分类建议与语言配置。
+
+---
+
+## 6. 隐私字段(Privacy tab)—— 已按真实行为起草
+
+### 6.1 单一用途描述(Single purpose description)
+
+> **One-line purpose**:Auto-fill login credentials for websites you configure, keeping all data encrypted and stored locally on your device.
+> **中文口径**:针对你配置的网站自动填充登录用户名和密码,所有数据经本地加密后仅保存在你设备上。
+
+### 6.2 权限理由(Permission justifications,逐权限)
+
+| 权限 | 真实用途(代码依据) |
+| --- | --- |
+| `storage` | 保存配置与解锁期间的会话数据(`chrome.storage.local` 密文 / `session` 明文仅内存) |
+| `activeTab` | 点击扩展图标时临时访问当前标签页,用于「填入当前域名」「在当前页面填充」 |
+| `scripting` | 按需向已授权网站注入填充脚本(无 manifest 级强制注入) |
+| `sidePanel` | 展示扩展侧边栏界面 |
+| `bookmarks` | 仅当你点击「从书签导入」时读取书签(`bookmark-import.ts` 调用 `chrome.bookmarks.getTree()`)批量生成域名配置 |
+
+未申请 `tabs`、`webRequest`、`history` 等无关权限。
+
+### 6.3 远程代码声明(Remote code)
+
+- 勾选 **No**:扩展不含、也不执行远程代码;全部逻辑打包在 zip 内。
+
+### 6.4 数据使用申报(Data usage / Data safety)
+
+| 申报项 | 如实填写 |
+| --- | --- |
+| 是否收集/传输用户数据 | 收集(仅用户主动录入的凭据与域名配置),**不传输** |
+| 收集的数据类型 | Passwords(密码)、Personal info – User IDs(用户名)、域名配置(用户提供,录入时产生) |
+| 数据用途 | 核心功能:登录表单自动填充(单一用途) |
+| 是否与第三方共享 | 否 |
+| 是否出售数据 | 否 |
+| 是否用于广告/分析 | 否 |
+| 采集是否可选/可删 | 是;删除条目或卸载扩展即清除 |
+| 加密 | 传输不适用(零网络请求);存储:主口令 PBKDF2-SHA256(20 万次迭代)派生 AES-GCM-256 密钥,密钥不可导出(`extractable: false`) |
+
+> 注意:公开向 Google 申报的口径与「隐私政策」「商店描述」必须一致(Listing Requirements 明确要求三者一致)。
+
+### 6.5 隐私政策 URL(Privacy policy)
+
+- 官方要求:处理任何用户数据的扩展必须在 Dashboard 提供**准确、最新**的隐私政策 URL;无需隐私政策时也须说明。
+- 本扩展收集密码,**必须提供隐私政策 URL**。
+- ✅ **隐私政策页面已备好**:`cws-store/privacy.html`(自包含、中英双语、联系邮箱已填、内嵌样式无外部依赖,已确认 `218.61.196.156:41695` 公网可达、仅 http)。
+- ⏳ **待你完成**:把 `cws-store/privacy.html` **提交并 push** 到远程 `master` 分支,确认仓库对匿名访客可读后,在 Privacy tab 填入 raw URL:
+ `http://218.61.196.156:41695/Chrome-extension/auto-login/raw/branch/master/cws-store/privacy.html`
+ (三处 URL 可填值与前置核对详见 `URL-填写清单.md`)
+- 托管后维护义务:政策实质变更时更新页面与官方要求的显著披露。
+
+### 6.6 需要"显著披露"的更新(2026-08-01 起执行的政策)
+
+2026 年 7 月 1 日官方发布、8 月 1 日生效的政策更新要点,已逐条核对:
+
+| 政策要点 | 本扩展符合情况 |
+| --- | --- |
+| 收集的数据严格限于披露的单一用途(Limited Use) | ✔ 仅用于自动填充 |
+| 所有数据收集须显著披露给用户 | ✔ 隐私政策 + 设置页"本机密码仅用于本地加密,不会上传到任何服务器"提示 |
+| 数据处理方式变更须主动披露 | ✔ 政策文档含变更说明条款(见 PRIVACY.md 第 7 节),后续若变更加版本并更新政策 |
+
+---
+
+## 7. 打包与构建
+
+| # | 项 | 说明 | 状态 |
+| --- | --- | --- | --- |
+| 7.1 | 版本号 | manifest/package.json 版本一致:1.0.0 | ✔ |
+| 7.2 | 构建命令 | `npm run build`(release 模式) | ✔ 由打包脚本自动执行 |
+| 7.3 | zip 生成 | `node scripts/package.mjs` → `release/auto-login-v1.0.0.zip` | ✔ 见第 8 节 |
+| 7.4 | 后续版本迭代 | `npm run release -- patch/minor/major` 同时同步 manifest/package.json/updates.xml | ✔ 既有脚本 |
+
+---
+
+## 8. 发布流程(首次上架操作顺序)
+
+1. 打开 [Chrome Web Store Developer Dashboard](https://chrome.google.com/webstore/devconsole),用开发者账号登录(已开 2FA)。
+2. **Add new item**(新增商品)→ Choose file → 选择 `release/auto-login-v1.0.0.zip` → Upload。
+3. 左侧菜单逐项填写:
+ - **Package**:只读,显示上传包信息(zip 有效则正常)。
+ - **Store Listing**:按第 3、5 节填写;上传图标、截图、促销图;选择语言为 zh-CN 与 en 并分别填描述。
+ - **Privacy**:按第 6 节填写单一用途、权限理由、远程代码=No、数据申报、粘贴隐私政策 URL。
+ - **Distribution**:免费(Free);地区默认全部或按需选择;可见范围选择 Public。
+ - **Test instructions**:如需可填写测试说明(安装后打开侧边栏设置密码→添加配置→授权站点→刷新目标页观察自动填充);密码管理类扩展建议填写以加速审核。
+4. 点击 **Submit for Review**(提交审核);如不想审核一过立即可见,可在确认弹窗取消"审核通过后自动发布",稍后手动发布。
+5. 审核通过后有 **30 天** 发布窗口,超时退回草稿需重新提交;审核时长不定(多数 1 天~数天),可在 Dashboard 查看状态并开启邮件通知。
+
+---
+
+## 9. 待你完成的清单(最终行动项)
+
+- [x] 已确认开发者账号开启两步验证(2FA)并支付 $5 一次性注册费(2026-09-24)
+- [ ] 将 `cws-store/privacy.html` 提交并 push 到远程 `master`,确认仓库匿名可读后,在 Privacy tab 填入 raw URL(见 `URL-填写清单.md`;已确认 `218.61.196.156:41695` 公网可达、仅 http)
+- [ ] 按规格截 3–5 张 1280x800 截图
+- [x] 制作 440x280 小促销图(必填)+ 1400x560 Marquee(可选)→ 已生成 `cws-store/promo/`(英文版;如需中文版可据 `promo_*.html` 改文案重导出)
+- [x] 复核/重制 128x128 商店图标(已像素实测:`icon128.png` 图形 96x96 居中、四周各 16px 透明边距,合规无需重制)
+- [ ] 在 Dashboard 上传 zip → 填写 Store Listing(主页/支持 URL 已备好) / Privacy / Distribution → Submit for Review
+
+---
+
+*核对表依据官方文档:Program Policies(含 2026-08-01 生效的 Limited Use 数据政策)、Privacy & data safety、Listing requirements、CWS dashboard listing、Supplying Images、Publish、Register。*
\ No newline at end of file
diff --git a/cws-store/02-隐私政策-Privacy-Policy.md b/cws-store/02-隐私政策-Privacy-Policy.md
new file mode 100644
index 0000000..c416b2b
--- /dev/null
+++ b/cws-store/02-隐私政策-Privacy-Policy.md
@@ -0,0 +1,180 @@
+# 隐私政策 / Privacy Policy — Auto Login Manager
+
+**扩展名称**:Auto Login Manager
+**版本**:1.0.0
+**生效日期**:2026-09-24
+**政策最后更新**:2026-09-24
+
+> 本文档用于 Chrome Web Store 上架隐私申报,与扩展仓库内 `PRIVACY.md` 口径一致。
+> 联系方式已填写(见下方「8. 联系方式」)。发布前请将本政策正文托管到公网 URL(GitHub Pages / Gitee Pages / 自有站点均可),再把该 URL 填入 Developer Dashboard 的 Privacy 字段。
+
+---
+
+## 目录
+
+- [中文](#中文)
+- [English](#english)
+
+---
+
+## 中文
+
+### 一句话说明
+
+本扩展(Auto Login Manager)是一个浏览器端自动填充工具:你为特定网站保存登录配置(域名、用户名、密码),本扩展在你访问已授权网站时自动填充登录表单。**所有凭据仅在设置本机口令后以 AES-GCM-256 密文保存在你自己的浏览器本机;本扩展不包含任何网络请求代码,不将任何数据上传到任何服务器。**
+
+### 1. 我们收集哪些数据
+
+**我们只处理你主动录入的数据,并且这些数据不会离开你的设备。**
+
+| 数据类型 | 是否收集 | 来源 | 用途 |
+| --- | --- | --- | --- |
+| 登录配置(域名/URL 匹配规则、用户名、密码、别名) | 是 | 你在扩展侧边栏手动录入,或通过「从书签导入」批量生成 | 核心功能:自动填充登录表单(单一用途) |
+| 环境信息(环境名称、环境内配置分组) | 是 | 你创建环境时录入 | 多环境配置管理 |
+| 设置项(自动提交、填充延迟、选择器、启用状态) | 是 | 你配置时录入 | 控制填充行为 |
+| 自动提交失败计数 | 是 | 扩展运行产生 | 防止账号因连续自动提交被锁定(纯本地计数) |
+| 浏览器书签 | 是(仅点击「从书签导入」时) | Chrome 书签 API | 仅在你主动触发时读取书签生成域名配置 |
+
+**明确不收集**:
+
+- 无网络请求:本扩展不含任何向外部服务器发送数据的代码(经代码审查确认,无 `fetch` / `XMLHttpRequest` / `WebSocket` / `sendBeacon` 调用)
+- 无统计分析、无崩溃上报、无广告、无第三方 SDK
+- 不读取浏览历史(未申请 `tabs` 权限;仅在你点击扩展图标时经 `activeTab` 临时访问当前标签页)
+- 不收集设备标识、位置、联系人、支付信息
+
+### 2. 数据保存在哪里
+
+| 数据 | 位置 | 说明 |
+| --- | --- | --- |
+| 域名配置、用户名、密码、环境信息 | `chrome.storage.local` | 设置本机口令后以 **AES-GCM-256 密文**保存 |
+| 解锁期间的明文配置 | `chrome.storage.session` | 仅内存,浏览器关闭即清除;10 分钟无操作自动锁定 |
+| 加密密钥句柄 | 扩展专属 IndexedDB | 存的是**不可导出**的密钥对象(`extractable: false`),无法读出原始密钥字节 |
+| 登录失败计数 | `chrome.storage.local` | 非敏感,仅用于失败次数限制 |
+
+主口令本身**不会被保存**到任何存储位置。它仅用于派生加密密钥,解锁后只保留派生结果。
+
+### 3. 加密方式
+
+- 密钥派生:PBKDF2-SHA256 + 随机盐(本机口令 **200,000** 次迭代;导出文件口令 100,000 次迭代)
+- 数据加密:AES-GCM-256(带完整性校验的认证加密)
+- 密钥属性:不可导出(`exportKey()` 按设计失败),只能用于加解密
+
+如果你忘记本机口令,**数据无法恢复**,这是加密设计的必然结果。
+
+### 4. 权限用途(与清单权限逐项对应)
+
+本扩展在 `manifest.json` 中声明以下权限,每一项都有真实用途:
+
+| 权限 | 用途 |
+| --- | --- |
+| `storage` | 保存加密配置(`storage.local`)与解锁期间的会话数据(`storage.session`) |
+| `activeTab` | 你点击扩展图标时**临时**访问当前标签页,用于「在当前页面填充」与「填入当前域名」 |
+| `scripting` | 在需要时按需注入填充脚本 |
+| `sidePanel` | 显示扩展侧边栏界面 |
+| `bookmarks` | 仅当你点击「从书签导入」时读取书签,用于批量生成域名配置 |
+
+**网站访问权限采取最小化设计**:本扩展未在安装时申请任何全站访问权限(manifest 仅含 `optional_host_permissions: ["*://*/*"]`)。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;**未授权的网站不会执行任何本扩展脚本**。你可以随时在 `chrome://extensions` 中撤销授权,撤销后该网站不再自动填充(手动填充仍可用)。
+
+**无强制内容注入**:本扩展的 manifest 中不包含 `content_scripts` 声明,不会在你未授权的情况下自动向任何网页注入脚本;填充脚本仅在已授权网站或你手动触发时按需注入。
+
+### 5. 数据的导出与删除
+
+- **导出**:由你主动触发,导出的文件保存在你指定的位置,可选择用文件口令加密后导出
+- **删除单条配置**:在侧边栏中删除即可
+- **删除全部数据**:卸载本扩展,或清除该扩展的存储数据(`chrome://extensions` → 扩展详情 → 清除数据)
+
+### 6. 第三方共享
+
+不存在。本扩展不与任何第三方共享数据,因为它不向外传输数据;不涉及数据出售、广告、跨站追踪。
+
+### 7. 政策变更
+
+若本政策发生实质性变更,将更新本文件顶部的「政策最后更新」日期,并随扩展版本更新一并发布;涉及数据处理方式变更时,将按 Chrome Web Store 政策要求主动进行显著披露。
+
+### 8. 联系方式
+
+- 支持 / 反馈:**chenxuanvictory@163.com**
+- 项目主页:**http://218.61.196.156:41695/Chrome-extension/auto-login.git**
+
+如有隐私相关问题,也可通过上述渠道联系我们,我们会在合理时间内回复。
+
+---
+
+## English
+
+### Summary
+
+Auto Login Manager is a browser-side auto-fill tool. You save login entries (domain, username, password) for websites you choose; the extension auto-fills the login form when you visit an authorized site. **All credentials are stored on your own machine, encrypted with AES-GCM-256 after you set a local master password. The extension contains no networking code and transmits nothing anywhere.**
+
+### 1. Data We Collect
+
+**We only handle data you enter yourself, and it never leaves your device.**
+
+| Data type | Collected | Source | Purpose |
+| --- | --- | --- | --- |
+| Login entries (domain / URL match rules, username, password, alias) | Yes | You type them into the side panel, or generate them in bulk via "import from bookmarks" | Core function: auto-fill login forms (single purpose) |
+| Environment info (environment names and config groups) | Yes | You create environments in the UI | Multi-environment config management |
+| Settings (auto-submit, fill delay, selectors, enabled state) | Yes | You configure them | Control fill behavior |
+| Auto-submit failure counters | Yes | Generated by the extension at runtime | Prevents account lockout from repeated auto-submits (local counter only) |
+| Browser bookmarks | Yes (only when you click "import from bookmarks") | Chrome bookmarks API | Read bookmarks only when you explicitly trigger the import |
+
+**Explicitly not collected**:
+
+- No network requests: the extension contains no code that sends data to any server (verified by code review: no `fetch` / `XMLHttpRequest` / `WebSocket` / `sendBeacon` calls)
+- No analytics, no crash reporting, no ads, no third-party SDKs
+- No browsing history (the `tabs` permission is not requested; the active tab is accessed temporarily via `activeTab` only when you click the extension icon)
+- No device identifiers, location, contacts, or payment information
+
+### 2. Where Data Is Stored
+
+| Data | Location | Notes |
+| --- | --- | --- |
+| Domain configs, usernames, passwords, environments | `chrome.storage.local` | Stored as **AES-GCM-256 ciphertext** once a master password is set |
+| Decrypted configs while unlocked | `chrome.storage.session` | In-memory only; cleared when the browser closes; auto-locks after 10 minutes of inactivity |
+| Encryption key handle | Extension-owned IndexedDB | A **non-extractable** key object; raw key bytes cannot be read out |
+| Login failure counters | `chrome.storage.local` | Non-sensitive; used only to throttle repeated auto-submits |
+
+The master password itself is **never written to any storage**. It is only used to derive the encryption key.
+
+### 3. Encryption
+
+- Key derivation: PBKDF2-SHA256 with a random salt (200,000 iterations for the master password; 100,000 for exported file passwords)
+- Data encryption: AES-GCM-256 (authenticated encryption with integrity checks)
+- Key property: non-extractable — `exportKey()` fails by design
+
+If you forget your master password, the data **cannot be recovered**. That is an inherent property of the encryption design.
+
+### 4. Permissions (mapped 1:1 to the declared permissions)
+
+| Permission | Purpose |
+| --- | --- |
+| `storage` | Save encrypted configs (`storage.local`) and unlocked session data (`storage.session`) |
+| `activeTab` | **Temporary** access to the active tab when you click the extension icon, for "fill current page" and "fill current domain" |
+| `scripting` | Inject the fill script on demand |
+| `sidePanel` | Render the side panel UI |
+| `bookmarks` | Read bookmarks only when you click "import from bookmarks", to generate domain configs in bulk |
+
+**Site access is minimal by design**: the extension does not request any install-time access to all websites (the manifest only declares `optional_host_permissions: ["*://*/*"]`). You are asked once, when you save a config for a domain, whether to allow access to that site. **No extension script runs on sites you have not authorized.** You can revoke grants at any time from `chrome://extensions`; revoked sites simply stop auto-filling (manual fill still works).
+
+**No forced content injection**: the manifest declares no `content_scripts`. The extension never injects scripts into any page without your authorization; fill scripts are injected on demand only on authorized sites or when you trigger fill manually.
+
+### 5. Export and Deletion
+
+- Export is always user-initiated; optional file-password encryption is available
+- Delete individual entries in the side panel
+- Delete everything by uninstalling the extension or clearing its storage data
+
+### 6. Third Parties
+
+None. The extension does not share data with any third party because it does not transmit data anywhere; no data selling, no ads, no cross-site tracking.
+
+### 7. Policy Changes
+
+Material changes will be reflected in the "Last updated" date at the top of this document and shipped with a new extension version. Changes to data handling practices will be proactively disclosed as required by Chrome Web Store policy.
+
+### 8. Contact
+
+- Support / feedback: **chenxuanvictory@163.com**
+- Project home: **http://218.61.196.156:41695/Chrome-extension/auto-login.git**
+
+For privacy-related questions, please contact us through the channels above; we will respond within a reasonable timeframe.
\ No newline at end of file
diff --git a/cws-store/03-商店列表材料-Store-Listing.md b/cws-store/03-商店列表材料-Store-Listing.md
new file mode 100644
index 0000000..9eee3d9
--- /dev/null
+++ b/cws-store/03-商店列表材料-Store-Listing.md
@@ -0,0 +1,138 @@
+# Auto Login Manager — Chrome Web Store 商店列表材料(中英双语)
+
+> 用途:本文件提供 Developer Dashboard「Store Listing」标签页所需的全部文案与配置建议,可直接复制粘贴。
+> 依据:扩展真实行为(manifest 权限、本地加密实现、无网络请求、按需注入),避免任何夸大或关键词堆砌。
+> 生成时间:2026-09-24
+
+---
+
+## 一、基础信息(通用字段)
+
+| 字段 | 填写值 | 说明 |
+| --- | --- | --- |
+| 扩展名称(Name) | **Auto Login Manager** | 建议保持与 manifest 品牌一致;商店与清单名称统一 |
+| 分类(Category) | **Productivity**(生产力) | 在控制台选项中选择 Productivity |
+| 语言(Language) | **zh-CN** 与 **en** | 扩展含 `_locales/zh_CN`、`_locales/en`,两种语言均可提供本地化描述;控制台逐语言录入 |
+| 主页 URL(Homepage) | **http://218.61.196.156:41695/Chrome-extension/auto-login** | Gitea 仓库 Web 首页(公网可达);若希望公网用户可访问更美观的页面,可后续改为公开站点 |
+| 支持 URL(Support URL) | **http://218.61.196.156:41695/Chrome-extension/auto-login** | 用户反馈入口(Gitea 仓库页,含 Issues 入口) |
+| 内容分级 | 不勾选 Mature | 无成人/敏感内容 |
+
+> 说明:控制台每种语言下可分别填写一套「详细描述 + 截图 + 视频」;小促销图与 Marquee 图不支持本地化,只传一次。
+
+---
+
+## 二、英语(en)
+
+### 2.1 详细描述(Detailed Description — English)
+
+> 建议:先放 1 句核心功能说明,再展开细节;避免同一关键词重复超过 5 次(官方反关键词堆砌要求)。
+
+**Draft (English description):**
+
+```
+Auto Login Manager fills the username and password on websites you have configured, so you
+can stay signed in without retyping credentials. Works from a side panel alongside the page.
+
+Privacy first: everything is stored on your device, encrypted locally. The extension makes
+no network requests, sends no data to any server, and uses no analytics or third-party SDKs.
+
+Core features
+
+- Domain rules: exact domains, wildcards (*.example.com), and path rules (oa.com/login/*)
+- Multiple environments: keep separate accounts for personal, test, and production sites;
+ pick the right one when several match
+- Auto-fill with optional auto-submit: fill username and password, then optionally click
+ the login button for you
+- On-demand injection only: no scripts run on sites you have not configured and authorized;
+ granting site access is a one-time per-domain prompt you can revoke anytime
+- Advanced form detection: CSS selectors, keyword heuristics, Shadow DOM, and login forms
+ inside iframes (SSO pages) are supported
+- SPA friendly: retries for up to 30 seconds while the page renders the form late, with
+ exponential backoff and graceful shutdown when the DOM stops changing
+- Captcha awareness: when a CAPTCHA / slider is detected, it fills the credentials but
+ never auto-submits; you complete the challenge and click login
+- Safety guard: after 3 consecutive auto-submits on the same domain it pauses auto-submit
+ (still fills) for 5 minutes to protect your account, and resets once login succeeds
+- Local encryption: PBKDF2-SHA256 (200,000 iterations) derives an AES-GCM-256 key; the key
+ is non-extractable and the master password is never written to disk
+- Auto-lock: after 10 minutes of inactivity the vault locks; decrypted data lives only in
+ memory (session storage) and is cleared when the browser closes
+- Bookmarks import: generate domain configs in bulk from your bookmarks
+- Bilingual UI: English and 简体中文
+
+Manual filling is available on any page you open, even without granting site access
+(activeTab permission), making it useful on the spot.
+```
+
+> 可省略「隐私/加密」整段以缩短篇幅;若保留,请与隐私政策、Data safety 申报保持完全一致。
+
+---
+
+## 三、中文(zh-CN)
+
+### 3.1 详细描述(Detailed Description — 简体中文)
+
+**文案草稿(中文描述):**
+
+```
+Auto Login Manager 能为你配置过的网站自动填写用户名和密码,从此不用每次重新输入账号信息。
+通过侧边栏即可与网页并排使用,添加配置、管理账号、一键填充。
+
+隐私优先:所有数据仅保存在本机并做本地加密。扩展没有任何网络请求代码,不会向任何服务器
+发送数据,无统计、无广告、无第三方 SDK。
+
+核心功能
+
+- 域名规则:支持精确域名、通配符(*.example.com)、路径规则(oa.com/login/*)
+- 多环境隔离:个人、测试、生产等环境分别保存账号,命中多条配置时弹出选择
+- 自动填充 + 可选自动提交:填入用户名密码后,可选择是否替你点击登录按钮
+- 按需注入:未配置且未授权的网站不会执行任何扩展脚本;站点授权按域名逐一询问,
+ 可随时在 chrome://extensions 撤销
+- 表单识别能力强:支持 CSS 选择器、关键词启发式、Shadow DOM 组件、iframe 内嵌登录框(SSO)
+- 适配 SPA 页面:表单晚渲染时最长重试 30 秒,带退避与空转保护,不影响大页面性能
+- 验证码感知:检测到验证码/滑块时只填充、不自动提交,由你完成验证后点击登录
+- 账号保护:同一域名连续自动提交 3 次后暂停自动提交 5 分钟(仍会填充),
+ 检测到登录成功自动清零计数
+- 本地加密:PBKDF2-SHA256(20 万次迭代)派生 AES-GCM-256 密钥;密钥不可导出,
+ 主口令不写入任何存储
+- 自动锁定:10 分钟无操作自动锁定;解密数据只存在于内存(session 存储),关浏览器即清除
+- 书签导入:从浏览器书签批量生成域名配置
+- 中英双语界面
+
+即使未授权站点,打开网页后也能用手动填充(基于 activeTab 临时权限),随开随用。
+```
+
+---
+
+## 四、扩展短描述(用于 manifest / 商店侧栏展示)
+
+商店列表中的「简短描述」取自 `manifest.json` 的 `description`(`__MSG_extDescription__`),当前已是双语:
+
+- **zh-CN**:针对特定域名自动填充用户名密码并完成登录,支持界面管理域名配置
+- **en**:Auto-fill username and password for specific domains and complete login. Supports managing domain configurations via UI.
+
+可直接沿用;如需更营销化的短描述,候选(en / zh):
+
+| 语言 | 候选短描述 | 建议 |
+| --- | --- | --- |
+| en | Fill credentials automatically, keep them encrypted on your device | 更口语、突出隐私卖点 |
+| en | Log in faster — auto-fill stored credentials for the domains you choose | 突出效率 |
+| zh-CN | 为指定网站自动填入账号密码,凭据本地加密,不上传任何服务器 | 突出隐私 |
+| zh-CN | 登录提速:为你配置的网站自动填写用户名密码并完成登录 | 突出效率 |
+
+> 注意:修改 `_locales/*/messages.json` 的 `extDescription` 会影响 manifest 描述,需随扩展包重新构建(npm run build + package);若仅改商店列表描述,则直接在控制台 Store Listing 中填写即可,无需动包。
+
+---
+
+## 五、提交质量控制(提交前自查)
+
+- [ ] 详细描述以一句话点明功能开头(官方推荐)
+- [ ] 中英文案口径一致(功能集合不变,避免控制台跨语言一致性告警)
+- [ ] 未使用关键词堆砌(同一词语句中被连续/过度重复)
+- [ ] 描述、隐私政策、Data safety 申报三者对「收集什么、存哪里、是否上传」的表述一致
+- [ ] 未宣称「极速/100% 安全」等绝对化或无法证明的措辞(避免审核驳回)
+- [ ] 已填写主页/支持 URL(建议为公开仓库页,便于审核人员核验与用户反馈)
+
+---
+
+*配套文件:01-上架材料核对表.md(所有字段来源与核对项)、02-隐私政策-Privacy-Policy.md、03-截图与宣传图规格说明.md。*
\ No newline at end of file
diff --git a/cws-store/04-截图与宣传图规格.md b/cws-store/04-截图与宣传图规格.md
new file mode 100644
index 0000000..0599a5f
--- /dev/null
+++ b/cws-store/04-截图与宣传图规格.md
@@ -0,0 +1,93 @@
+# Auto Login Manager — 商店截图与宣传图规格及截屏指引
+
+> 用途:按官方规格准备 Chrome Web Store 展示素材(截图、小促销图、Marquee、商店图标)。
+> 官方要求(2026 生效口径):截图必须真实反映扩展功能;禁止使用带边框/圆角/阴影(全出血直角铺满);禁止堆叠多张截图拼图。
+> 生成时间:2026-09-24
+
+---
+
+## 一、规格速查表
+
+| 素材 | 尺寸 | 格式 | 数量 | 是否必填 | 备注 |
+| --- | --- | --- | --- | --- | --- |
+| 商店截图(Screenshot) | 1280x800 或 640x400 | PNG/JPEG | 至少 1,建议 3–5 | 必填 | 横向;直角全出血(无圆角/边框/阴影),图片内容铺满整张 |
+| 小促销图(Small Promo Tile) | 440x280 | PNG | 1 | 必填 | 商店首页/搜索展示;文字尽量少,不能被裁切 |
+| Marquee 促销图 | 1400x560 | PNG | 1 | 可选 | 商店精选位展示;建议电商/商店背景留白充足 |
+| 商店图标(Icon) | 128x128 | PNG | 1 | 必填 | 图形约占中心 96x96,四周留 ≥16px 透明边距(Chrome 会裁圆角/内缩,四周贴边会显示不全) |
+| 宣传视频(Promo Video) | 1280x720 | 不限(托管于 YouTube) | 1 | 可选 | 仅当 Store Listing 选择语言含 en 时需提供;zh-CN 不支持 |
+
+> 提示:截图上传 1280x800 即可(高分屏展示清晰);务必以**实际运行画面**为准,不得伪造不存在的界面或夸大功能效果。
+
+---
+
+## 二、商店截图内容建议(针对本扩展)
+
+按照「第一屏讲清楚是什么 → 中间屏展示关键功能 → 最后屏讲隐私/多环境」的叙事顺序,建议 4–5 张:
+
+| # | 场景 | 操作步骤 | 画面要点 |
+| --- | --- | --- | --- |
+| 1 | 主界面总览 | 打开任意网页(如 example.com 登录页),点击扩展图标从侧边栏打开面板 | 侧边栏「域名列表 + 配置入口」与网页并排同屏;体现「与页面同屏使用」的卖点 |
+| 2 | 添加域名配置 | 在面板中点击「添加域名」,展开表单填写规则(如 `*.example.com`、用户名、密码、是否自动提交) | 表单 + 规则类型切换可见;展示精确/通配符/路径的多选能力 |
+| 3 | 自动填充效果 | 打开已配置域名的登录页,点击面板「填充」按钮或自动填充 | 用户名/密码框已被填入;若同时展示自动提交,需在描述中说明做了自动提交 |
+| 4 | 多环境账号选择 | 配置同域多环境(个人/测试/生产)后再次访问 | 命中多条配置时的「选择账号」浮层;体现多环境隔离 |
+| 5 | 隐私与加密 | 打开扩展的「设置/Vault 锁定」界面 | 展示主口令输入/自动锁定 10 分钟、解密数据只存内存等;截图中避免出现真实密码明文(可用圆点占位符) |
+
+**截屏建议工具**:Chrome DevTools → 右上角 ⋮ → Run command → 输入 `Capture full size screenshot`(再配合 `emulate device` 设定 1280x800 视口),或使用系统截图软件裁切到 1280x800。
+
+**截图合规注意**:
+- 截图中不要出现**真实账号的真实密码明文**(用点号 `••••` 代替,避免泄露与审核疑虑)。
+- 不使用测试站点 URL 时,请用公开示例域名(example.com / example.org);若使用真实网站(如 GitHub 登录页),请确保不截取他人隐私数据。
+- 截图与图内文字语言应与你当前录入的语言一致(en 截图配英文界面,zh-CN 截图可配中文界面)。
+
+---
+
+## 三、小促销图(440x280,必填)制作建议
+
+- 用途:商店列表与搜索结果卡片;显示面积小,文字与图形务必简洁。
+- 构图:左侧/中央放扩展开机主界面缩略(侧边栏面板),右侧放 1 条品牌文案,如:
+ - EN:`Auto Login Manager` + `Fill credentials, keep them encrypted on your device`
+ - 中文:`Auto Login Manager` + `自动填充账号密码,本地加密保存`
+- 规则:四周留安全边距(至少 16px),避免文字被裁切;不要加圆角/边框;不要做成多截图拼接。
+- 工具:Figma / Canva / PowerPoint 导出 PNG,或使用 `baidu-image-gen` 按 440x280 生成插画背景后叠加真实界面截图。
+
+---
+
+## 四、Marquee(1400x560,可选)制作建议
+
+- 用途:商店精选位横版大图;有背景展示空间。
+- 构图:左侧大标题 + 右侧界面/功能特写,或居中「图标 + 产品名 + 一句卖点」。
+- 建议背景使用品牌主色(与图标一致)渐变色块,避免纯白内容被吞。
+- 内容形式示例:`Log in with one click` / `Local encryption. No servers.`(若已在上架描述中使用本地加密卖点,保持一致口径)。
+
+---
+
+## 五、商店图标(128x128)复核/重制建议
+
+- 现状:`icons/icon128.png` 为完整方形图形,符合「图形占 96x96、四周透明边 16px」要求的概率存疑,**建议复核或重制**:
+ 1. 打开 `icons/icon128.png`,检查最外圈 16px 是否透明;
+ 2. 若非透明,用编辑器把画布扩到 160x160 并把原图居中到 96x96 区域导出 128x128(或直接用设计工具重新按 16px 安全边距重绘);
+ 3. 导出 PNG(不要用 JPEG,透明通道会失效),压缩后体积极小即可。
+- 同组图标:`icon16/icon48/icon128` 三档需同时更新,保持视觉一致(Chrome 工具栏、上下文菜单、商店展示用同一图形)。
+
+---
+
+## 六、宣传视频(可选,en 语言建议提供)
+
+- 规格:YouTube 视频,1280x720 以上,时长建议 ≤60 秒。
+- 建议脚本大纲:
+ 1. 人物打开某网站登录页 → 侧边栏打开面板 → 一键填充 → 自动提交进入后台(约 15s);
+ 2. 展示多环境账号选择(约 15s);
+ 3. 展示验证码只填充不提交(约 10s);
+ 4. 隐私卡片式收尾:`Everything stays on your device. No servers involved.`(约 10s)。
+- 录屏工具:系统自带录屏 / OBS 录制 1280x800 视口,避免录到书签栏等无关内容。
+
+---
+
+## 七、交付前检查清单
+
+- [ ] 截图 1280x800 或 640x400:PNG/JPEG、直角全出血、内容铺满、无水印
+- [ ] 截图无密码明文、无私人数据
+- [ ] 小促销图 440x280:存在、无文字裁切、无边框圆角
+- [ ] Marquee 1400x560:存在(可选)、无文字裁切
+- [ ] 图标 128x128:图形居中 ≤96x96、四周透明 ≥16px、三档尺寸(16/48/128)同步
+- [ ] 图片语言与对应语言的 Store Listing 描述一致
\ No newline at end of file
diff --git a/cws-store/URL-填写清单.md b/cws-store/URL-填写清单.md
new file mode 100644
index 0000000..5b997fc
--- /dev/null
+++ b/cws-store/URL-填写清单.md
@@ -0,0 +1,48 @@
+# URL 填写清单 — Auto Login Manager 上架环境
+
+> 已确认 `218.61.196.156:41695` 为公网可达地址(用户提供,外网可访问),且当前 Gitea **仅支持 http(无 https)**。
+> 因此以下 URL 一律使用 `http://`。若日后为该 Gitea 启用 HTTPS,请把前缀整体替换为 `https://`。
+
+---
+
+## 0. 提交前必须满足的 2 个前置(很重要)
+
+- [ ] **隐私政策页面需匿名可访问**:审核团队和用户是"无登录"的访客。你的 Gitea 仓库若为 **private**,`/raw/` 地址会要求登录而无法打开。请确保:
+ - 方式 A(推荐):把仓库 `Chrome-extension/auto-login` 设为 **public**(可见性改为公开),这样 `raw` 页匿名可读;
+ - 或方式 B:仅需该文件可匿名访问——但 Gitea 无可单独公开单文件的配置,故实际仍需仓库 public 或借助其他静态托管。
+- [ ] **`cws-store/privacy.html` 已提交并推送(push)到远程 `master` 分支**。push 后请先以无痕/未登录窗口打开下面「隐私政策 URL」验证能直接渲染出页面,再填入 Dashboard。
+
+---
+
+## 1. 三处 URL 可填值(复制即用)
+
+| Dashboard 字段 | 填写值(复制) | 说明 |
+| --- | --- | --- |
+| **主页 URL**(Homepage) | `http://218.61.196.156:41695/Chrome-extension/auto-login` | Gitea 仓库 Web 首页(非 `.git` 裸仓库地址) |
+| **支持 URL**(Support URL) | `http://218.61.196.156:41695/Chrome-extension/auto-login` | 用户反馈/帮助入口(Gitea 仓库页含 Issues 入口) |
+| **隐私政策 URL**(Privacy policy) | `http://218.61.196.156:41695/Chrome-extension/auto-login/raw/branch/master/cws-store/privacy.html` | Gitea `/raw/` 直接以 HTML 页面返回,浏览器即可渲染 |
+
+> 隐私政策 URL 备选(Gitea 内嵌渲染,需登录态,不推荐给审核):
+> `http://218.61.196.156:41695/Chrome-extension/auto-login/src/branch/master/cws-store/privacy.html`
+
+---
+
+## 2. 你需要做的一步 git 操作(本次仅说明,不代办)
+
+请把新增/改动的上架材料提交并推送到远程仓库(在你确认无误后执行):
+
+```bash
+git add cws-store/privacy.html cws-store/promo cws-store/*.md
+git commit -m "docs(cws): 上架材料:促销图 + 隐私政策HTML + URL清单"
+git push
+```
+
+推送后,用浏览器(**无痕模式**)打开隐私政策 URL 验证:
+- 应能直接看到纯 HTML 的隐私政策页面(中文在前、English 在后),无需登录。
+
+---
+
+## 3. http / https 风险提示(如实告知)
+
+- 当前地址为 `http://`。Chrome 桌面端对 http 页面会标注"不安全";Chrome Web Store 审核与用户点击链接时体验略差,官方更推荐 HTTPS 隐私政策页。
+- 只要内容可正常匿名渲染,纯 http 一般**不影响**上架审核通过;是否接受由你的产品决策。若后续想消除该负面提示,可为这台 Gitea 配置 HTTPS 反向代理(如 Nginx + 免费 Let's Encrypt 证书),届时把第 1 节 URL 前缀换成 `https://` 即可,其余不变。
\ No newline at end of file
diff --git a/cws-store/privacy.html b/cws-store/privacy.html
new file mode 100644
index 0000000..f9dc416
--- /dev/null
+++ b/cws-store/privacy.html
@@ -0,0 +1,218 @@
+
+
+
+
+
+隐私政策 / Privacy Policy — Auto Login Manager
+
+
+
+
+
+
隐私政策 / Privacy Policy
+
Auto Login Manager — Chrome 扩展(Manifest V3)v1.0.0
+
生效日期 Effective: 2026-09-24
+
最后更新 Last updated: 2026-09-24
+
+
+
+
+
+
+ 中 文 / ZH-CN
+ 一句话说明
+ 本扩展(Auto Login Manager)是一个浏览器端自动填充工具:你为特定网站保存登录配置(域名、用户名、密码),本扩展在你访问已授权网站时自动填充登录表单。所有凭据仅在设置本机口令后以 AES-GCM-256 密文 保存在你自己的浏览器本机;本扩展不包含任何网络请求代码,不将任何数据上传到任何服务器。
+
+ 1. 我们收集哪些数据
+ 我们只处理你主动录入的数据,并且这些数据不会离开你的设备。
+
+ 数据类型 是否收集 来源 用途
+ 登录配置(域名/URL 匹配规则、用户名、密码、别名) 是 你在扩展侧边栏手动录入,或通过「从书签导入」批量生成 核心功能:自动填充登录表单(单一用途)
+ 环境信息(环境名称、环境内配置分组) 是 你创建环境时录入 多环境配置管理
+ 设置项(自动提交、填充延迟、选择器、启用状态) 是 你配置时录入 控制填充行为
+ 自动提交失败计数 是 扩展运行产生 防止账号因连续自动提交被锁定(纯本地计数)
+ 浏览器书签 是(仅点击「从书签导入」时) Chrome 书签 API 仅在你主动触发时读取书签生成域名配置
+
+ 明确不收集:
+
+ 无网络请求:本扩展不含任何向外部服务器发送数据的代码(经代码审查确认,无 fetch / XMLHttpRequest / WebSocket / sendBeacon 调用)
+ 无统计分析、无崩溃上报、无广告、无第三方 SDK
+ 不读取浏览历史(未申请 tabs 权限;仅在你点击扩展图标时经 activeTab 临时访问当前标签页)
+ 不收集设备标识、位置、联系人、支付信息
+
+
+ 2. 数据保存在哪里
+
+ 数据 位置 说明
+ 域名配置、用户名、密码、环境信息 chrome.storage.local设置本机口令后以 AES-GCM-256 密文保存
+ 解锁期间的明文配置 chrome.storage.session仅内存,浏览器关闭即清除;10 分钟无操作自动锁定
+ 加密密钥句柄 扩展专属 IndexedDB 存的是不可导出的密钥对象(extractable: false),无法读出原始密钥字节
+ 登录失败计数 chrome.storage.local非敏感,仅用于失败次数限制
+
+ 主口令本身不会被保存 到任何存储位置。它仅用于派生加密密钥,解锁后只保留派生结果。
+
+ 3. 加密方式
+
+ 密钥派生:PBKDF2-SHA256 + 随机盐(本机口令 200,000 次迭代;导出文件口令 100,000 次迭代)
+ 数据加密:AES-GCM-256(带完整性校验的认证加密)
+ 密钥属性:不可导出(exportKey() 按设计失败),只能用于加解密
+
+ 如果你忘记本机口令,数据无法恢复 ,这是加密设计的必然结果。
+
+ 4. 权限用途(与清单权限逐项对应)
+
+ 权限 用途
+ storage保存加密配置(storage.local)与解锁期间的会话数据(storage.session)
+ activeTab你点击扩展图标时临时访问当前标签页,用于「在当前页面填充」与「填入当前域名」
+ scripting在需要时按需注入填充脚本
+ sidePanel显示扩展侧边栏界面
+ bookmarks仅当你点击「从书签导入」时读取书签,用于批量生成域名配置
+
+ 网站访问权限采取最小化设计: 本扩展未在安装时申请任何全站访问权限(manifest 仅含 optional_host_permissions: ["*://*/*"])。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;未授权的网站不会执行任何本扩展脚本。你可以随时在 chrome://extensions 中撤销授权,撤销后该网站不再自动填充(手动填充仍可用)。
+ 无强制内容注入: 本扩展的 manifest 中不包含 content_scripts 声明,不会在你未授权的情况下自动向任何网页注入脚本;填充脚本仅在已授权网站或你手动触发时按需注入。
+
+ 5. 数据的导出与删除
+
+ 导出:由你主动触发,导出的文件保存在你指定的位置,可选择用文件口令加密后导出
+ 删除单条配置:在侧边栏中删除即可
+ 删除全部数据:卸载本扩展,或清除该扩展的存储数据(chrome://extensions → 扩展详情 → 清除数据)
+
+
+ 6. 第三方共享
+ 不存在。本扩展不与任何第三方共享数据,因为它不向外传输数据;不涉及数据出售、广告、跨站追踪。
+
+ 7. 政策变更
+ 若本政策发生实质性变更,将更新本文件顶部的「政策最后更新」日期,并随扩展版本更新一并发布;涉及数据处理方式变更时,将按 Chrome Web Store 政策要求主动进行显著披露。
+
+ 8. 联系方式
+
+ 如有隐私相关问题,也可通过上述渠道联系我们,我们会在合理时间内回复。
+
+
+
+
+ E N G L I S H
+ Summary
+ Auto Login Manager is a browser-side auto-fill tool. You save login entries (domain, username, password) for websites you choose; the extension auto-fills the login form when you visit an authorized site. All credentials are stored on your own machine, encrypted with AES-GCM-256 after you set a local master password. The extension contains no networking code and transmits nothing anywhere.
+
+ 1. Data We Collect
+ We only handle data you enter yourself, and it never leaves your device.
+
+ Data type Collected Source Purpose
+ Login entries (domain / URL match rules, username, password, alias) Yes You type them into the side panel, or generate them in bulk via "import from bookmarks" Core function: auto-fill login forms (single purpose)
+ Environment info (environment names and config groups) Yes You create environments in the UI Multi-environment config management
+ Settings (auto-submit, fill delay, selectors, enabled state) Yes You configure them Control fill behavior
+ Auto-submit failure counters Yes Generated by the extension at runtime Prevents account lockout from repeated auto-submits (local counter only)
+ Browser bookmarks Yes (only when you click "import from bookmarks") Chrome bookmarks API Read bookmarks only when you explicitly trigger the import
+
+ Explicitly not collected:
+
+ No network requests: the extension contains no code that sends data to any server (verified by code review: no fetch / XMLHttpRequest / WebSocket / sendBeacon calls)
+ No analytics, no crash reporting, no ads, no third-party SDKs
+ No browsing history (the tabs permission is not requested; the active tab is accessed temporarily via activeTab only when you click the extension icon)
+ No device identifiers, location, contacts, or payment information
+
+
+ 2. Where Data Is Stored
+
+ Data Location Notes
+ Domain configs, usernames, passwords, environments chrome.storage.localStored as AES-GCM-256 ciphertext once a master password is set
+ Decrypted configs while unlocked chrome.storage.sessionIn-memory only; cleared when the browser closes; auto-locks after 10 minutes of inactivity
+ Encryption key handle Extension-owned IndexedDB A non-extractable key object; raw key bytes cannot be read out
+ Login failure counters chrome.storage.localNon-sensitive; used only to throttle repeated auto-submits
+
+ The master password itself is never written to any storage . It is only used to derive the encryption key.
+
+ 3. Encryption
+
+ Key derivation: PBKDF2-SHA256 with a random salt (200,000 iterations for the master password; 100,000 for exported file passwords)
+ Data encryption: AES-GCM-256 (authenticated encryption with integrity checks)
+ Key property: non-extractable — exportKey() fails by design
+
+ If you forget your master password, the data cannot be recovered . That is an inherent property of the encryption design.
+
+ 4. Permissions (mapped 1:1 to the declared permissions)
+
+ Permission Purpose
+ storageSave encrypted configs (storage.local) and unlocked session data (storage.session)
+ activeTabTemporary access to the active tab when you click the extension icon, for "fill current page" and "fill current domain"
+ scriptingInject the fill script on demand
+ sidePanelRender the side panel UI
+ bookmarksRead bookmarks only when you click "import from bookmarks", to generate domain configs in bulk
+
+ Site access is minimal by design: the extension does not request any install-time access to all websites (the manifest only declares optional_host_permissions: ["*://*/*"]). You are asked once, when you save a config for a domain, whether to allow access to that site. No extension script runs on sites you have not authorized. You can revoke grants at any time from chrome://extensions; revoked sites simply stop auto-filling (manual fill still works).
+ No forced content injection: the manifest declares no content_scripts. The extension never injects scripts into any page without your authorization; fill scripts are injected on demand only on authorized sites or when you trigger fill manually.
+
+ 5. Export and Deletion
+
+ Export is always user-initiated; optional file-password encryption is available
+ Delete individual entries in the side panel
+ Delete everything by uninstalling the extension or clearing its storage data
+
+
+ 6. Third Parties
+ None. The extension does not share data with any third party because it does not transmit data anywhere; no data selling, no ads, no cross-site tracking.
+
+ 7. Policy Changes
+ Material changes will be reflected in the "Last updated" date at the top of this document and shipped with a new extension version. Changes to data handling practices will be proactively disclosed as required by Chrome Web Store policy.
+
+ 8. Contact
+
+ For privacy-related questions, please contact us through the channels above; we will respond within a reasonable timeframe.
+
+
+ Auto Login Manager · Privacy Policy v1.0.0 · 2026-09-24
+
+
+
\ No newline at end of file
diff --git a/cws-store/promo/README.md b/cws-store/promo/README.md
new file mode 100644
index 0000000..5d314d0
--- /dev/null
+++ b/cws-store/promo/README.md
@@ -0,0 +1,32 @@
+# 促销图素材(Auto Login Manager — Chrome Web Store)
+
+本目录为商店促销图交付物,尺寸已按官方规格**像素级精确**,可直接上传。
+
+| 文件 | 用途 | 尺寸 | 必填 | 状态 |
+| --- | --- | --- | --- | --- |
+| `promo-440x280.png` | 小促销图 Small promo tile | 440x280 | 是 | ✔ 可直接上传 |
+| `promo-1400x560.png` | Marquee 大促销图 | 1400x560 | 可选 | ✔ 可直接上传 |
+| `promo_440.html` / `promo_1400.html` | 设计源文件 | – | – | 可改源码重新导出 |
+
+## 素材说明
+
+- **设计语言**:采用扩展真实界面视觉(深色主题 `#1a1a2e`、强调色 `#e94560`、卡片 `#16213e`),右侧面板为按真实 `popup.css` 样式绘制的界面缩略,如实反映产品功能(域名配置列表 + 一键填充 + 多环境)。
+- **文案语言**:促销图不分语言仅上传一次,采用英文主文案,与商店 `en` 列表口径一致(隐私卖点、单一用途表述与隐私政策一致)。
+- **全出血直角**:无圆角边框、无外框、无 padding,背景铺满整幅,符合 Chrome 官方 "full bleed" 要求。
+- **安全边距**:文字均保留安全区内,已在 440x280 / 1400x560 各分辨率下核对无裁切。
+
+## 使用 / 再导出方法(如需微调)
+
+1. 用任意编辑器改 `promo_440.html` / `promo_1400.html`(CSS 变量、文案、面板条目)。
+2. 用 Chrome headless 重新导出 PNG:
+ ```powershell
+ & "C:\Program Files\Google\Chrome\Application\chrome.exe" --headless=new --disable-gpu `
+ --hide-scrollbars --force-device-scale-factor=1 `
+ --window-size=440,280 `
+ --screenshot="promo-440x280.png" `
+ "file:///E:/gitea/Chrome%20extension/auto-login/cws-store/promo/promo_440.html"
+ # 1400x560 同理改 --window-size=1400,560 与对应 html
+ ```
+3. 若你希望促销图改用**真实运行的侧边栏截图**而非仿真面板,可把货真价实的界面截图替换进面板区域(把 `` 换成 `
`),重导出即可。
+
+> 提示:若商店中你给 zh-CN 语言也填了一套截图,促销图仍只需上传一次(官方不做本地化)。如需要中文文案版的促销图,可把左侧卖点与面板文字换成中文后重新导出本 README 提供的命令。
\ No newline at end of file
diff --git a/cws-store/promo/promo-1400x560.png b/cws-store/promo/promo-1400x560.png
new file mode 100644
index 0000000..f7e9787
Binary files /dev/null and b/cws-store/promo/promo-1400x560.png differ
diff --git a/cws-store/promo/promo-440x280.png b/cws-store/promo/promo-440x280.png
new file mode 100644
index 0000000..e49ebb7
Binary files /dev/null and b/cws-store/promo/promo-440x280.png differ
diff --git a/cws-store/promo/promo_1400.html b/cws-store/promo/promo_1400.html
new file mode 100644
index 0000000..194a36d
--- /dev/null
+++ b/cws-store/promo/promo_1400.html
@@ -0,0 +1,85 @@
+
+
+
+
+
+
+
+
+
+
A U T O L O G I N M A N A G E R Auto Login Manager
+
+
Log in with one click.Local encryption. No servers.
+
Store credentials per site and environment.
+ Fill and submit automatically on authorized pages — only on sites you choose.
+
+
AES-256 local vault
+
Wildcard & path rules
+
Multi-environment
+
+
+
+
Auto Login Manager
+
+
+
+
git.example.com
dev ••••••
+
mail.example.com
me ••••••
+
portal.example.cn
ops ••••••
+
+
Fill current page
+
+
+
\ No newline at end of file
diff --git a/cws-store/promo/promo_440.html b/cws-store/promo/promo_440.html
new file mode 100644
index 0000000..d0b7927
--- /dev/null
+++ b/cws-store/promo/promo_440.html
@@ -0,0 +1,64 @@
+
+
+
+
+
+
+
+
+
AUTO LOGIN MANAGER Auto Login Manager
+
+
Auto-fill logins.Encrypted on your device.
+
No servers. No tracking. Multi-environment accounts.
+
Fill credentials in one click
+
+
+
Auto Login Manager
+
+
+
+
git.example.com
dev ••••••
+
mail.example.com
me ••••••
+
+
Fill current page
+
+
+
\ No newline at end of file