优化
This commit is contained in:
+126
@@ -0,0 +1,126 @@
|
||||
# 隐私政策 / Privacy Policy
|
||||
|
||||
**Auto Login Manager**(下称"本扩展")
|
||||
|
||||
最后更新:2026-09-17
|
||||
|
||||
---
|
||||
|
||||
## 中文
|
||||
|
||||
### 一句话说明
|
||||
|
||||
本扩展**不收集、不存储、不上传**任何用户数据到任何服务器。所有数据仅保存在你自己的浏览器本机。
|
||||
|
||||
### 1. 我们收集哪些数据
|
||||
|
||||
**不收集任何数据。** 具体而言:
|
||||
|
||||
- 没有网络请求:本扩展不包含任何向外部服务器发送数据的代码
|
||||
- 没有统计分析、没有崩溃上报、没有广告、没有第三方 SDK
|
||||
- 不读取你的浏览历史(仅在你主动点击时读取当前标签页的地址与标题)
|
||||
- 不收集设备标识、位置、联系人等任何信息
|
||||
|
||||
### 2. 数据保存在哪里
|
||||
|
||||
| 数据 | 位置 | 说明 |
|
||||
| --- | --- | --- |
|
||||
| 域名配置、用户名、密码、环境信息 | `chrome.storage.local` | 设置本机口令后以 **AES-GCM-256 密文**保存 |
|
||||
| 解锁期间的明文配置 | `chrome.storage.session` | 仅内存,浏览器关闭即清除 |
|
||||
| 加密密钥句柄 | 扩展的 IndexedDB | 存的是**不可导出**的密钥对象(`extractable: false`),无法被读出原始密钥 |
|
||||
| 登录失败计数 | `chrome.storage.local` | 非敏感,仅用于失败次数限制 |
|
||||
|
||||
主口令本身**不会**被保存到任何位置。它仅用于派生加密密钥,解锁后只保留派生结果。
|
||||
|
||||
### 3. 加密方式
|
||||
|
||||
- 密钥派生:PBKDF2-SHA256,随机盐(本机口令 20 万次迭代;导出文件的口令 10 万次迭代)
|
||||
- 数据加密:AES-GCM-256(带完整性校验的认证加密)
|
||||
- 密钥属性:不可导出(`exportKey()` 会失败),只能用于加解密
|
||||
|
||||
如果你忘记本机口令,**数据无法恢复**,这是加密设计的必然结果。
|
||||
|
||||
### 4. 权限用途
|
||||
|
||||
本扩展申请以下权限,用途均限于实现自动填充功能:
|
||||
|
||||
- `storage`:保存配置与解锁期间的会话数据
|
||||
- `tabs`:读取当前标签页地址 / 标题,用于「填入当前域名」与登录页匹配
|
||||
- `scripting`:在需要时注入填充脚本
|
||||
- `activeTab`:你点击扩展时临时访问当前标签页
|
||||
- `sidePanel`:显示侧边栏界面
|
||||
- `bookmarks`:仅在你点击「从书签导入」时读取书签,用于批量生成域名配置
|
||||
- 访问所有网站的权限(`<all_urls>`):因为你可以为任意域名配置自动登录;**实际注入范围严格限定为你配置过的域名**,未配置的网站不会执行任何本扩展脚本
|
||||
|
||||
### 5. 数据的导出与删除
|
||||
|
||||
- **导出**:由你主动触发,导出的文件保存在你指定的位置,可选择用文件口令加密
|
||||
- **删除单条配置**:在侧边栏中删除即可
|
||||
- **删除全部数据**:卸载本扩展,或在浏览器中清除该扩展的存储数据
|
||||
|
||||
### 6. 第三方共享
|
||||
|
||||
不存在。本扩展不与任何第三方共享数据,因为它根本不向外传输数据。
|
||||
|
||||
### 7. 政策变更
|
||||
|
||||
若本政策发生实质性变更,将在本文件顶部的"最后更新"日期中体现,并随扩展版本更新一并发布。
|
||||
|
||||
### 8. 联系方式
|
||||
|
||||
如有疑问,请在本项目仓库提交 Issue。
|
||||
|
||||
---
|
||||
|
||||
## English
|
||||
|
||||
### Summary
|
||||
|
||||
This extension **does not collect, store, or transmit** any user data. Everything stays in your own browser on your own machine.
|
||||
|
||||
### Data We Collect
|
||||
|
||||
**None.** There are no network requests, no analytics, no crash reporting, no ads, and no third-party SDKs.
|
||||
|
||||
### Where Data Is Stored
|
||||
|
||||
| Data | Location | Notes |
|
||||
| --- | --- | --- |
|
||||
| Domain configs, usernames, passwords, environments | `chrome.storage.local` | Stored as **AES-GCM-256 ciphertext** once a master password is set |
|
||||
| Decrypted configs while unlocked | `chrome.storage.session` | In-memory only, cleared when the browser closes |
|
||||
| Encryption key handle | Extension IndexedDB | A **non-extractable** key object; the raw key bytes cannot be read out |
|
||||
| Login failure counters | `chrome.storage.local` | Non-sensitive, used to throttle repeated auto-submits |
|
||||
|
||||
The master password itself is **never** written to any storage. It is only used to derive the encryption key.
|
||||
|
||||
### Encryption
|
||||
|
||||
- Key derivation: PBKDF2-SHA256 with a random salt (200,000 iterations for the master password; 100,000 for exported file passwords)
|
||||
- Encryption: AES-GCM-256 (authenticated encryption)
|
||||
- Key property: non-extractable — `exportKey()` fails by design
|
||||
|
||||
If you forget your master password, the data **cannot be recovered**. That is an inherent property of the encryption design.
|
||||
|
||||
### Permissions
|
||||
|
||||
- `storage` — save configs and unlocked session data
|
||||
- `tabs` — read the active tab's URL/title for "fill current domain" and login-page matching
|
||||
- `scripting` — inject the fill script on demand
|
||||
- `activeTab` — temporary access to the active tab when you click the extension
|
||||
- `sidePanel` — render the side panel UI
|
||||
- `bookmarks` — read bookmarks only when you click "import from bookmarks"
|
||||
- `<all_urls>` — you may configure auto-login for any domain; the **actual injection scope is limited to domains you configured**. No script runs on unconfigured sites.
|
||||
|
||||
### Export and Deletion
|
||||
|
||||
- Export is always user-initiated; optional file-password encryption is available
|
||||
- Delete individual entries in the side panel
|
||||
- Delete everything by uninstalling the extension or clearing its storage data
|
||||
|
||||
### Third Parties
|
||||
|
||||
None. The extension does not transmit data anywhere.
|
||||
|
||||
### Contact
|
||||
|
||||
Please open an issue in this project's repository.
|
||||
Reference in New Issue
Block a user