Files
auto-login/cws-store/03-商店列表材料-Store-Listing.md
yinjun.chen1 459b613dc3 docs: 新增 Chrome Web Store 上架材料
核对表/隐私政策/商店列表材料/截图与宣传图规格

privacy.html:自包含中英双语隐私政策页面;URL-填写清单.md:主页/支持/隐私政策三处可填 URL;promo/:440x280 小促销图与 1400x560 Marquee(英文版,尺寸实测合规)
2026-09-24 15:22:06 +08:00

138 lines
7.8 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Auto Login Manager — Chrome Web Store 商店列表材料(中英双语)
> 用途:本文件提供 Developer Dashboard「Store Listing」标签页所需的全部文案与配置建议,可直接复制粘贴。
> 依据:扩展真实行为(manifest 权限、本地加密实现、无网络请求、按需注入),避免任何夸大或关键词堆砌。
> 生成时间:2026-09-24
---
## 一、基础信息(通用字段)
| 字段 | 填写值 | 说明 |
| --- | --- | --- |
| 扩展名称(Name) | **Auto Login Manager** | 建议保持与 manifest 品牌一致;商店与清单名称统一 |
| 分类(Category) | **Productivity**(生产力) | 在控制台选项中选择 Productivity |
| 语言(Language) | **zh-CN** 与 **en** | 扩展含 `_locales/zh_CN`、`_locales/en`,两种语言均可提供本地化描述;控制台逐语言录入 |
| 主页 URL(Homepage) | **http://218.61.196.156:41695/Chrome-extension/auto-login** | Gitea 仓库 Web 首页(公网可达);若希望公网用户可访问更美观的页面,可后续改为公开站点 |
| 支持 URL(Support URL) | **http://218.61.196.156:41695/Chrome-extension/auto-login** | 用户反馈入口(Gitea 仓库页,含 Issues 入口) |
| 内容分级 | 不勾选 Mature | 无成人/敏感内容 |
> 说明:控制台每种语言下可分别填写一套「详细描述 + 截图 + 视频」;小促销图与 Marquee 图不支持本地化,只传一次。
---
## 二、英语(en)
### 2.1 详细描述(Detailed Description — English)
> 建议:先放 1 句核心功能说明,再展开细节;避免同一关键词重复超过 5 次(官方反关键词堆砌要求)。
**Draft (English description):**
```
Auto Login Manager fills the username and password on websites you have configured, so you
can stay signed in without retyping credentials. Works from a side panel alongside the page.
Privacy first: everything is stored on your device, encrypted locally. The extension makes
no network requests, sends no data to any server, and uses no analytics or third-party SDKs.
Core features
- Domain rules: exact domains, wildcards (*.example.com), and path rules (oa.com/login/*)
- Multiple environments: keep separate accounts for personal, test, and production sites;
pick the right one when several match
- Auto-fill with optional auto-submit: fill username and password, then optionally click
the login button for you
- On-demand injection only: no scripts run on sites you have not configured and authorized;
granting site access is a one-time per-domain prompt you can revoke anytime
- Advanced form detection: CSS selectors, keyword heuristics, Shadow DOM, and login forms
inside iframes (SSO pages) are supported
- SPA friendly: retries for up to 30 seconds while the page renders the form late, with
exponential backoff and graceful shutdown when the DOM stops changing
- Captcha awareness: when a CAPTCHA / slider is detected, it fills the credentials but
never auto-submits; you complete the challenge and click login
- Safety guard: after 3 consecutive auto-submits on the same domain it pauses auto-submit
(still fills) for 5 minutes to protect your account, and resets once login succeeds
- Local encryption: PBKDF2-SHA256 (200,000 iterations) derives an AES-GCM-256 key; the key
is non-extractable and the master password is never written to disk
- Auto-lock: after 10 minutes of inactivity the vault locks; decrypted data lives only in
memory (session storage) and is cleared when the browser closes
- Bookmarks import: generate domain configs in bulk from your bookmarks
- Bilingual UI: English and 简体中文
Manual filling is available on any page you open, even without granting site access
(activeTab permission), making it useful on the spot.
```
> 可省略「隐私/加密」整段以缩短篇幅;若保留,请与隐私政策、Data safety 申报保持完全一致。
---
## 三、中文(zh-CN)
### 3.1 详细描述(Detailed Description — 简体中文)
**文案草稿(中文描述):**
```
Auto Login Manager 能为你配置过的网站自动填写用户名和密码,从此不用每次重新输入账号信息。
通过侧边栏即可与网页并排使用,添加配置、管理账号、一键填充。
隐私优先:所有数据仅保存在本机并做本地加密。扩展没有任何网络请求代码,不会向任何服务器
发送数据,无统计、无广告、无第三方 SDK。
核心功能
- 域名规则:支持精确域名、通配符(*.example.com)、路径规则(oa.com/login/*)
- 多环境隔离:个人、测试、生产等环境分别保存账号,命中多条配置时弹出选择
- 自动填充 + 可选自动提交:填入用户名密码后,可选择是否替你点击登录按钮
- 按需注入:未配置且未授权的网站不会执行任何扩展脚本;站点授权按域名逐一询问,
可随时在 chrome://extensions 撤销
- 表单识别能力强:支持 CSS 选择器、关键词启发式、Shadow DOM 组件、iframe 内嵌登录框(SSO)
- 适配 SPA 页面:表单晚渲染时最长重试 30 秒,带退避与空转保护,不影响大页面性能
- 验证码感知:检测到验证码/滑块时只填充、不自动提交,由你完成验证后点击登录
- 账号保护:同一域名连续自动提交 3 次后暂停自动提交 5 分钟(仍会填充),
检测到登录成功自动清零计数
- 本地加密:PBKDF2-SHA256(20 万次迭代)派生 AES-GCM-256 密钥;密钥不可导出,
主口令不写入任何存储
- 自动锁定:10 分钟无操作自动锁定;解密数据只存在于内存(session 存储),关浏览器即清除
- 书签导入:从浏览器书签批量生成域名配置
- 中英双语界面
即使未授权站点,打开网页后也能用手动填充(基于 activeTab 临时权限),随开随用。
```
---
## 四、扩展短描述(用于 manifest / 商店侧栏展示)
商店列表中的「简短描述」取自 `manifest.json` 的 `description`(`__MSG_extDescription__`),当前已是双语:
- **zh-CN**:针对特定域名自动填充用户名密码并完成登录,支持界面管理域名配置
- **en**:Auto-fill username and password for specific domains and complete login. Supports managing domain configurations via UI.
可直接沿用;如需更营销化的短描述,候选(en / zh):
| 语言 | 候选短描述 | 建议 |
| --- | --- | --- |
| en | Fill credentials automatically, keep them encrypted on your device | 更口语、突出隐私卖点 |
| en | Log in faster — auto-fill stored credentials for the domains you choose | 突出效率 |
| zh-CN | 为指定网站自动填入账号密码,凭据本地加密,不上传任何服务器 | 突出隐私 |
| zh-CN | 登录提速:为你配置的网站自动填写用户名密码并完成登录 | 突出效率 |
> 注意:修改 `_locales/*/messages.json` 的 `extDescription` 会影响 manifest 描述,需随扩展包重新构建(npm run build + package);若仅改商店列表描述,则直接在控制台 Store Listing 中填写即可,无需动包。
---
## 五、提交质量控制(提交前自查)
- [ ] 详细描述以一句话点明功能开头(官方推荐)
- [ ] 中英文案口径一致(功能集合不变,避免控制台跨语言一致性告警)
- [ ] 未使用关键词堆砌(同一词语句中被连续/过度重复)
- [ ] 描述、隐私政策、Data safety 申报三者对「收集什么、存哪里、是否上传」的表述一致
- [ ] 未宣称「极速/100% 安全」等绝对化或无法证明的措辞(避免审核驳回)
- [ ] 已填写主页/支持 URL(建议为公开仓库页,便于审核人员核验与用户反馈)
---
*配套文件:01-上架材料核对表.md(所有字段来源与核对项)、02-隐私政策-Privacy-Policy.md、03-截图与宣传图规格说明.md。*