安全与权限: - 站点访问权限改为 optional_host_permissions,保存配置时逐域名授权;移除 host_permissions 与 tabs,安装提示不再出现全站数据访问与浏览记录 - 主口令不再写入 storage.session,改用 IndexedDB 中不可导出的 CryptoKey 句柄恢复解锁,锁定即丢弃 - content script 注入范围只注册已授权域名,并随权限变化即时收敛 自动登录: - 支持 iframe 内的登录表单:脚本注入所有帧,逐帧按自身地址匹配配置 - 手动填充改为逐帧探测,定向发送到真正含密码框的帧 - 限流修正:只在真正触发提交后计数;判定登录成功后立即清零;达到上限时页面给出可见提示;重置判断只看启用中的配置 - SPA 重试改为 DOM 变更门控 + 退避,并单独监听已发现的 Shadow Root 工程化与文档: - 引入 ESLint(扁平配置)与 Prettier,CI 增加 lint 与 format:check - 信息类日志改为 debugLog(默认静默,chrome.storage.local.debugLog 开关) - 测试 123 → 128 用例(新增权限、iframe、限流相关用例) - README / PRIVACY / CHANGELOG 同步
6.4 KiB
隐私政策 / Privacy Policy
Auto Login Manager(下称"本扩展")
最后更新:2026-09-17
中文
一句话说明
本扩展不收集、不存储、不上传任何用户数据到任何服务器。所有数据仅保存在你自己的浏览器本机。
1. 我们收集哪些数据
不收集任何数据。 具体而言:
- 没有网络请求:本扩展不包含任何向外部服务器发送数据的代码
- 没有统计分析、没有崩溃上报、没有广告、没有第三方 SDK
- 不读取你的浏览历史(仅在你主动点击时读取当前标签页的地址与标题)
- 不收集设备标识、位置、联系人等任何信息
2. 数据保存在哪里
| 数据 | 位置 | 说明 |
|---|---|---|
| 域名配置、用户名、密码、环境信息 | chrome.storage.local |
设置本机口令后以 AES-GCM-256 密文保存 |
| 解锁期间的明文配置 | chrome.storage.session |
仅内存,浏览器关闭即清除 |
| 加密密钥句柄 | 扩展的 IndexedDB | 存的是不可导出的密钥对象(extractable: false),无法被读出原始密钥 |
| 登录失败计数 | chrome.storage.local |
非敏感,仅用于失败次数限制 |
主口令本身不会被保存到任何位置。它仅用于派生加密密钥,解锁后只保留派生结果。
3. 加密方式
- 密钥派生:PBKDF2-SHA256,随机盐(本机口令 20 万次迭代;导出文件的口令 10 万次迭代)
- 数据加密:AES-GCM-256(带完整性校验的认证加密)
- 密钥属性:不可导出(
exportKey()会失败),只能用于加解密
如果你忘记本机口令,数据无法恢复,这是加密设计的必然结果。
4. 权限用途
本扩展申请以下权限,用途均限于实现自动填充功能:
storage:保存配置与解锁期间的会话数据activeTab:你点击扩展图标时临时访问当前标签页,用于「在当前页面填充」与「填入当前域名」scripting:在需要时注入填充脚本sidePanel:显示侧边栏界面bookmarks:仅在你点击「从书签导入」时读取书签,用于批量生成域名配置- 网站访问权限(
optional_host_permissions):本扩展不声明安装时生效的全站访问权限。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;未授权的网站不会执行任何本扩展脚本。你可以随时在chrome://extensions中撤销这些授权,撤销后该网站不再自动填充(手动填充仍可用)
在你已授权的网站内,脚本会注入到该页面的所有框架(含 iframe),以便填充内嵌在 iframe 中的登录表单(如 SSO 登录页)。每个框架都会用自己的地址去匹配你配置的域名,不匹配的框架不会做任何填充操作。
本扩展未声明 tabs 权限,因此不会读取你的浏览记录。
5. 数据的导出与删除
- 导出:由你主动触发,导出的文件保存在你指定的位置,可选择用文件口令加密
- 删除单条配置:在侧边栏中删除即可
- 删除全部数据:卸载本扩展,或在浏览器中清除该扩展的存储数据
6. 第三方共享
不存在。本扩展不与任何第三方共享数据,因为它根本不向外传输数据。
7. 政策变更
若本政策发生实质性变更,将在本文件顶部的"最后更新"日期中体现,并随扩展版本更新一并发布。
8. 联系方式
如有疑问,请在本项目仓库提交 Issue。
English
Summary
This extension does not collect, store, or transmit any user data. Everything stays in your own browser on your own machine.
Data We Collect
None. There are no network requests, no analytics, no crash reporting, no ads, and no third-party SDKs.
Where Data Is Stored
| Data | Location | Notes |
|---|---|---|
| Domain configs, usernames, passwords, environments | chrome.storage.local |
Stored as AES-GCM-256 ciphertext once a master password is set |
| Decrypted configs while unlocked | chrome.storage.session |
In-memory only, cleared when the browser closes |
| Encryption key handle | Extension IndexedDB | A non-extractable key object; the raw key bytes cannot be read out |
| Login failure counters | chrome.storage.local |
Non-sensitive, used to throttle repeated auto-submits |
The master password itself is never written to any storage. It is only used to derive the encryption key.
Encryption
- Key derivation: PBKDF2-SHA256 with a random salt (200,000 iterations for the master password; 100,000 for exported file passwords)
- Encryption: AES-GCM-256 (authenticated encryption)
- Key property: non-extractable —
exportKey()fails by design
If you forget your master password, the data cannot be recovered. That is an inherent property of the encryption design.
Permissions
storage— save configs and unlocked session dataactiveTab— temporary access to the active tab when you click the extension icon, used for "fill current page" and "fill current domain"scripting— inject the fill script on demandsidePanel— render the side panel UIbookmarks— read bookmarks only when you click "import from bookmarks"- Site access (
optional_host_permissions) — this extension does not request install-time access to all websites. You are asked once, when you save a config for a domain, whether to allow access to that site. No script runs on sites you have not authorized. You can revoke these grants at any time fromchrome://extensions; revoked sites simply stop auto-filling (manual fill still works).
On sites you have authorized, the script is injected into every frame of the page (including iframes) so that login forms embedded in an iframe (such as SSO pages) can be filled. Each frame matches your configured domains against its own URL; frames that do not match perform no filling at all.
The tabs permission is not requested, so your browsing history is not read.
Export and Deletion
- Export is always user-initiated; optional file-password encryption is available
- Delete individual entries in the side panel
- Delete everything by uninstalling the extension or clearing its storage data
Third Parties
None. The extension does not transmit data anywhere.
Contact
Please open an issue in this project's repository.