From f6b21461e9273484de2fb0aadc3e231b4da317a3 Mon Sep 17 00:00:00 2001 From: leeguooooo Date: Tue, 9 Jun 2026 19:03:10 +0900 Subject: [PATCH] feat(connect): pivot extension install to Chrome Web Store path MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Verified on Chrome 149 (unmanaged macOS): a force-install policy pointing at a SELF-HOSTED crx is tagged [BLOCKED] in chrome://policy ("Error, Warning") — Chrome refuses off-Web-Store force-installs on non-cloud-managed browsers. So the self-hosted-crx approach cannot work on consumer Chrome; the extension must ship via the Chrome Web Store (same reason codex/claude do). - UPDATE_URL -> Chrome Web Store update endpoint; add STORE_URL (one-click Add to Chrome) as the guaranteed path + headless fallback - install instructions now offer: A) one-click store link, B) silent profile force-install (works once published), with Load-unpacked as the pre-publish stopgap - build extensions/ab-connect.zip (CWS upload package; manifest "key" kept so the published id stays ciiljdlhdpfckdcfkphgmfalanpdejep) - extensions/store/{SUBMISSION.html,privacy.html}: full listing copy, permission justifications (debugger is the review-sensitive one), privacy policy - drop dead self-hosted extensions/updates.xml; pack-extension.sh now builds the zip Not released yet — force-install only works after the store listing is Published. --- cli/src/connect.rs | 32 +++++--- extensions/ab-connect.zip | Bin 0 -> 7209 bytes extensions/store/SUBMISSION.html | 133 +++++++++++++++++++++++++++++++ extensions/store/privacy.html | 77 ++++++++++++++++++ extensions/updates.xml | 13 --- scripts/pack-extension.sh | 47 ++++++----- 6 files changed, 255 insertions(+), 47 deletions(-) create mode 100644 extensions/ab-connect.zip create mode 100644 extensions/store/SUBMISSION.html create mode 100644 extensions/store/privacy.html delete mode 100644 extensions/updates.xml diff --git a/cli/src/connect.rs b/cli/src/connect.rs index 11c59fb..b0c11c2 100644 --- a/cli/src/connect.rs +++ b/cli/src/connect.rs @@ -24,14 +24,17 @@ pub const HOST_NAME: &str = "com.agent_browser.connect"; /// that extension talk to this host, and the force-install policy references it. pub const EXTENSION_ID: &str = "ciiljdlhdpfckdcfkphgmfalanpdejep"; -/// Omaha/gupdate update manifest for the signed `ab-connect.crx`. The macOS -/// configuration profile force-installs the extension from here, so no -/// `chrome://extensions` "Load unpacked" GUI step is ever needed. Chrome 142+ -/// removed `--load-extension`, and macOS has blocked local-`.crx` external -/// installs since Chrome 44 — a policy `update_url` is the only GUI-free path -/// left into the real, logged-in profile. -pub const UPDATE_URL: &str = - "https://raw.githubusercontent.com/leeguooooo/agent-browser-stealth/main/extensions/updates.xml"; +/// Update URL the force-install policy points at. MUST be the Chrome Web Store +/// endpoint: Chrome 149 tags any **off-Web-Store** force-installed extension +/// `[BLOCKED]` on an unmanaged browser (verified on macOS — chrome://policy shows +/// `[BLOCKED]…` / "Error, Warning"). Self-hosting a `.crx` therefore does NOT +/// work on consumer Chrome; the extension must be published to the Web Store, and +/// then this policy force-installs it silently (Web Store extensions are allowed). +pub const UPDATE_URL: &str = "https://clients2.google.com/service/update2/crx"; + +/// Public Web Store listing — the guaranteed one-click "Add to Chrome" path, +/// and the fallback when the force-install profile can't be approved headlessly. +pub const STORE_URL: &str = "https://chromewebstore.google.com/detail/ciiljdlhdpfckdcfkphgmfalanpdejep"; /// Stable identifiers for the generated Chrome configuration profile, so a /// re-install replaces (rather than duplicates) it in System Settings. @@ -94,11 +97,14 @@ pub fn run_connect(args: &[String], json: bool) { println!("\n✓ Chrome force-install profile written:\n {}", path.display()); if cfg!(target_os = "macos") { println!( - "\nOne-time step (no file dialog, ever): approve the profile, then restart Chrome.\n\ - System Settings → General → Device Management (or Privacy & Security →\n\ - Profiles) → double-click \"agent-browser connect\" → Install.\n\ - After approval Chrome force-installs the extension on next launch and\n\ - keeps it up to date — no token, no per-use confirmation." + "\nGet the extension into Chrome (one-time). Either:\n\ + A) One click: open {STORE_URL}\n and press \"Add to Chrome\".\n\ + B) Silent: approve the profile, then restart Chrome —\n \ + System Settings → General → Device Management → double-click\n \ + \"agent-browser connect\" → Install. Chrome then force-installs +\n \ + auto-updates it (no token, no per-use confirmation).\n\ + Both need the extension published to the Web Store; until then use\n \ + chrome://extensions → Developer mode → Load unpacked → extensions/ab-connect." ); } } diff --git a/extensions/ab-connect.zip b/extensions/ab-connect.zip new file mode 100644 index 0000000000000000000000000000000000000000..3d0618b5eb2152b72f3ab36c4ec68cd4e8e2dd38 GIT binary patch literal 7209 zcmbW61yo!~m&Y4-cL|chdA-GH9?gVQz5ZqmpU=6|D7G`#4 zGc)_`x4Y+^dhhi+r+%lp?!9&Yw@O(K4jvx>03ZX%Li_c)llqgoFaUrZCIA2fKn^fA z0$H0o*}K}Auvj^3sG|VjUiQ&jy?SV_9%uj<_){1F;J5BQI#9a>Ny58|0^$M*2|A8+ zDv1at>DFOe>srge*`-?*msA|yYArSL7c$xeHZZq!Se3Kpvq;dmUH9R^4_y(s%?y>2 z*kN7CoaV!q!>%qaG~a{2mUL-nzXCIfmmcf !Pt+=tHido#1S#rMkExHuMtTe!Hq z^IzAFr6VfFpArq@&X1H+VMq?!j1XmwFZ_!JkWSaRwK26;7u6!IG=imCm! zj2Z17&&@vTgklKjgH@$fz?W|dZ)8oq!1>}LNw;yBG933Pj!HW6k8=q(U zp28GudNsixdgE1n4Ax7Su;w&3rl63kL@CL$ z&3XR!qJ*-AKlp;Ka7CDOD|KF&edSV7>J~K`mkcwU2CEt5l0hUYoPmVT6Gam+SYxN0 z*WK{I9YNHBFHxgv@R1N25LcOEG82J+*t|Pm-UR}s9G;m@AZdnj$@xfzfaLhh+)F=rBG-kBFOcybJYW8)v0jvcjkjl0 zH|-~#q4}KRq7bR+SK?P^V0ORZsNt)}imR37Ab&nu&}NR^A;}W`kC+-OL2M4xbJQuMed*6jVe<)}X(CSyXfw zSmR40G;YtwTM)oYP;SeHd;I8dikhz#6_q z-6I9QLrBYG@`Oe67D2RXxuYB6$Ql%sto5lqPGZzJl^3mop)`BSGQrPoGL)U*6b#Y} z+ES1Ff=8qfAj*G#x8Tp-9gU)d1R8aN8mDjP*d+KJZJ}LWIM0C(WR9j14FzvHbC3FW zOQa5SXGg8NjdAFbp?!|Nn8XM(oks?1ma^pc(ghbX9BnNO zt9BnZxtgeZNJM~K~=Mo!mUcj?}HhF2SdW{DBFr5V-hSdJ1}N;_Q9 zCvYz_JkhMq*&~@&%(k1BgSom^C!2!JXyU#%;~PBHlmIH)7AC&X=5IaU~xZGr-j zT<;W+#*Jo2tv@W#^~=4V3xt%7#gkipm3>-nO~xXB5>(JS+T^t!j7YvYicpO^@uaNx zO?QKA+2^|@T0#_r6fYLr0FkEfB=o1uZ-+iJT_6jXXA|0T4XRA4J7v%|Tz?XiOa~UKAwN;b^d4jSE#Mtu{LC?oqBJ9vv>_ zsX3z=*k!AHFP6ak^R~A2_LK|K#4JCK_Du=9R z7GP%557akN#X0Q-DKOuZw~d zk>Vn?quAf2(@pGUP+#hYpfxwl$U}fzfo+FWxEBW_b#7kf93aEcI3Jlur>1aaFsL4aW<4^4IzrO@nJMN|~~r zh|TV831WMnfcnrU{R(l_deK!$xNs7E?DQesJ0fBH@c1=$8P3*&hv<`4Y?M7oE-xNsXH0 zO{Lv?xP}P{5`;R?C)j(r?g~NF zoY_)`Ig$;d1;z>JhkJuAd`Rtp+ggG+pX&6BijoFO)%~K~1Nt3csTI*Z9bkt;C?jvb z$v2G!q>r2IUMr{E5qjr?Q3C^OFuQl0zbmeCGtjM%b-g#*a@IYzDly2Kb6VvEI_fX< zseAO+9P=N4faTD~9B7w~YrD~XxxMx!ywy)3*++L3F)qt<(GiEH&oa)M7sfk3+SvBV zmjKhU2m^;LXtgkLTlJjMLRT|4WqunO#)wE!u^^qg?Ipp84p)>&T7^dmZem zMVk{qpb4RGVa?rLB8m*!|vYEO` zY5;m0Jq9Cn)Jz(ki<9hf#0NQ!rK>l zb89V4={GGAawguqDqvBy37KldDbakD?Y3_RWQF)hU`2EvfK0C$y!e+Fy7`hd)s32; zhl@?PKI;mh)`-hkWBoyx1;(6_XSc!INzyU)QG(=)rfWE1mx$_vz4WIgU=sb#6`h89 zbQB1oHY$4-yc5ktVaLH7VPcjIAzHn5&sZl_d=2SG-sW^GHIY8gv(fTInU95P z@f0mLzD<5gttCJsWvR}%K;ufGqD|IP#@G(t_~a}Pm;EJy{8CR%v&GV)OGvF<8@^$w zkB;c{MIWPdbk``Fm>oXZn4c?E$N5j@3S3J%&)5PM37b9#k^ID?>2kcRH`Y|g1+xy5tyYfi!!U-Tp6MBIU$6SiDQ4H>+ZIaW5JPr$;M`Nqee%*@PJ;Jp z5j;Vk1A~;1O#E(&o^*ItW=`HaM{)5t+O4>sypG)KebphVI=--IQ)eo?2|Pm6{#@Kt z6mSEt>QmYGGchLL8)z69$8FA zt@D{z)!V1Ywz3#c4J^cRM0OuUy(#erTKkF7I{A)f4~I2awcjs)>o|Y)>NB6MmxDpj z7?k6rg{{Xd)!W58I-96C-F9~k1PNMB#v{WzWB=xSSP+a@($Jf&_LGmCg`8`?5`#Y1 z0ojsOi%LxSnx|H}S1?PImHyxhy^RV5*|1+9k@>b>&jK;`SIXy{0&vDjJ2yynCp3GU zO#?^4gRGzWeP^ez(#PP7f6AnSaky!e%h@Z9TlH`#h@~hopV3gmlC4Co@TH`k1%++i zX=m*nw|}GC7`;4S@jL&>JFT^~ZI$mDEKRGqF5*n-Wu89u+3D52FbhFz;kS=(Q%^A~ zmhCY*E0wk*iw{qCu*R#}8%8gWnWI?uhcRV}?_c+-9>lay(^`Fd=ZEkt_R^$UD?F+t z50miTCl-GGhKWk6rVYlucA=7{;fC!1uvAHgTdUD>=fAXl1M_eUeKqHEYfp4b_XD z6pcS;8kG4}IW$L-Y2sPFR6VONFh7=4UjVG1DUn3YOWjZ^KU9LK50xMQknGm4_uI>V z-Vh%uK}(RmoipoiB_Mk-z12kRKT5#A_HT1>OF((34j&u#pZy;x>@Qgy?9BfpWvu^$ z6sD{wg@H=?I2a5WX>rwuC-!4QMtrza9^V^1JP?iLq{IRDk5^V}LEOWaHW_gdb)F~? zkk|qe$^z`^xu(nv0j&t;Zi%dEIUe2#o$Yac^Y=$84Pmq6hajuL;ek5AmkTMk4pD4p z{{HXpzqI+9iM!F_$sdm`QX!h8221piR94+zzrGPlA%j0>dIkpv*L8p75!y?Jb?8Y6 z!}XooU`Ma7uNwk^00lgsIFiN!2SAmya`8bWtbF(<02v8I@p4gM;Nz73UYtLg zL}V@^%JyM8o&GVUTs;47N}=cn&YM3zt{Ve^tEVRpD6r#*RD&IeG+oJl^>B>!H1_U9 zA@@{`!2P3sbo9ub43=nWlBj+Z+|md~o8E*dXch5} zE5CszEDVNg<}U@#KN+hp+tIDNn+GopWWF%?aQfQ!H76YW_o1t6$;O<# z-R2Ja^?FRB_q@{KE3It4XZa^9Q!AUzlm*a{xaW6{bt`RNcQ6z*6G;JHKk*NA zBOr^z;z!+t&x#z~fv(MN}Y`k7s-Z~e=1mU9v?66drCo)6| zRiZ6vXL-0>cIjAZ?(X{M?XrhLw|6$HhZ(a`{^ljTcQ2QCAG}2HAHmJZ@qZ6))Zd&W zqNKPD@YmoLjvaZ7ZJe^l*#26LC@O*?6?2!t+P$QC-Mq<{nL;$;R1e2mW|pQ@dwqD< zD)!;MNXF3H=o$`MM4>cNy0n${vyDqQDyplkcVaO;ohZ03!_j-NSeI3{ct#f}jC80P zHi@OLx|SO4qC_Lm@W$~1fL$#DzEM$;fuch@%=h_}hApMil4BjE*->l5xz1%nUzu@G z_;K7Z^~|@qUU>LoczX62aNc?kz$pzZx z%}%oAi>Rb2l<2C6qVS6eWIpukoojcNCq4w}HQeu;pSDJJmS(2TE)QFu_IAJJtCVSa ztH<`Y%}-yoA*UQ+?6yrth6=iH!8<=In%gO^pfhM97TCgvgmgEILChWOwt8qw1E^U6ka0@@JY)NjRvP^W6hC>! z6VF`5OJ>W^GCMhb3Am&Sbjpj@93gra%g=y3L83SX@}b7>fDXY$z@J+3SqGal_AnFg zf*5d(ce>=>_QJ-9Nn1k!a~dfStH>8-@ai;Wc(%w9;daK_A$2phaKT^nL+!7dEVho< zqRN#Ne9N~9>~d5rv0S-RbtTqUbZUln*|o^cE^U}!N}TNSO>~NEyfxV{#=f2plKcK_ z`~1yvDCX7l^1k?Uneg4yXOw4L@M!{?7>%>}c;Zokqe~vO4X^t&T;-CR%cW<1VfF)0 z89=#Bxr-l6o^H1yO*3|8*Frq9TW5dfG+UOa(OS)uZ2hp&C=?@+7O^PZSmTmO4bq6i zq^wET$P0?%P$sN-pPSx1aEhD7u=3m_bE(y3YE#0lJeS1irj3_8^s_FTl2@#K8DqaF zFTWG0$IaHAib;n!3N(lQO3jKOBRe4e^Ku?9aA8jJ%x=DeIGcn-qS$oa(bD@pTmzQddYUaNGu+_NNSB7i2}I);DmsJn;yla&idO&SaP^ z-)$yT^-0noG%(2i9JKsq;EWNLP{1=vZr&4{4@T-}HS2fU&fX9#oCq~ipSy@7T#ntY z0)8_iUdZW8>GWOhGgiz~l8-#n&n_;>SKBFPp_jC}A0%(WKoqx|b|qI44H51Cm4-Cm z_UmPqHh^>=78lY74@Y@OLyAi3GGY=ewkE%Mwp$CmmHR{cn`hg`b|}KKV~6bfhNBn& z-!3(0AUhlg8-MD~9jq7A)t*;)jplSr?IW7mJvRlEZ&8>}_HVn-B-3J}H+0_xDO*92 zYvm55!P%c{5^$+Ft&r5T$|-;m{kTD0KvGKP3qUjJX-EDnf?C_glM8fdIiR#|2I zDsUDV{|FR+Bzc@)B`7f`;OglD!)$~WBpP4N&G>8vmdp{~36%~=Zmb_C?h=n_XU){weO_`@g$oyVeLj~T%|0$2^um!D%j1j;5 zez!d@u;m8$Nr<=^#iz|*ICNBO@XB~Jy~thzqR0m49mSjhM)bn#WTxM9Kga4q4O>V( zN~|F@p_#wC(B8I?zIpO3Oune?VeNr|rGWcaM=!*WG7#`!EPv&|6n~1PxepNuj>APqW&vM`ztja>yHsW zQvVRR|2yhm71ys+b(~+R?0@L5{~h+PDf(Be7v8VfKN9x8r~WhR{7(Jd?za!~^tT-J vfc$Ur&#$iZ&rtsrxj+Q?HSiyBkAeRW(<3| + + + + +Chrome Web Store 提交指南 — agent-browser connect + + + +
+

Chrome Web Store 提交指南

+
agent-browser connect · 上传包 extensions/ab-connect.zip · id 锁定为 ciiljdlhdpfckdcfkphgmfalanpdejep
+
+ +

为什么必须走商店:实测 Chrome 149 在非企业托管的 Mac 上,会把"非 Web Store"的 force-install 扩展直接标成 [BLOCKED]。商店扩展不受此限。这也是 codex / claude 扩展都发商店的原因。

+ +
+ 评审风险(务必知道): 本扩展用了 debugger 权限,这是 Chrome Web Store 审核最严的权限之一。理由必须写清楚"只在用户本机、用户主动发指令时驱动用户自己的标签页,无远程服务器"。类似工具(如 claude-in-chrome)能过审,但可能被多问一轮、审核时间偏长(几天到一两周)。 +
+ +

一、前置(你来做,一次性)

+
    +
  1. 用一个 Google 账号登录 https://chrome.google.com/webstore/devconsole
  2. +
  3. 首次需付 $5 一次性开发者注册费
  4. +
  5. (隐私政策需要一个公开 URL,见第四节 —— 我可以帮你开 GitHub Pages 托管 privacy.html)
  6. +
+ +

二、上传

+
    +
  1. devconsole → New item → 上传 extensions/ab-connect.zip
  2. +
  3. 上传后确认分配到的 Item ID = ciiljdlhdpfckdcfkphgmfalanpdejep(因为 manifest 里保留了 key,id 会被锁成这个,native messaging 的 allowed_origins 才对得上)。若 id 不是这个,告诉我,我重签。
  4. +
+ +

三、商店信息(直接复制以下文案)

+ +

名称 / Name

+
agent-browser connect
+ +

简介 / Summary(≤132 字符)

+
Let your own agent-browser CLI drive your logged-in Chrome — a local automation bridge. No remote server, no token.
+ +

详细描述 / Description

+
agent-browser connect is the in-browser half of the open-source agent-browser CLI. It lets the
+command-line tool you installed on this same computer automate the Chrome you're already logged
+into — opening pages, clicking, filling forms, reading the DOM — driven entirely by you.
+
+How it works
+- The extension talks ONLY to the local agent-browser CLI over Chrome native messaging (a local
+  inter-process channel — no network socket, no token, no remote server).
+- When you run an automation command, the extension relays Chrome DevTools Protocol operations to
+  the tab you target, then returns the result to the CLI.
+
+Privacy
+- No analytics, no trackers, no data collection.
+- Nothing is sent to any remote server. The only message peer is the local CLI.
+- Source is open (Apache-2.0): https://github.com/leeguooooo/agent-browser-stealth
+
+You need the agent-browser CLI installed and paired (run: agent-browser extension install) for this
+extension to do anything.
+ +

类别 / Category

+
Developer Tools
+ +

语言 / Language

+
English
+ +

四、隐私实践(Privacy practices 标签页 —— 必填)

+ +

Single purpose(单一用途)

+
Bridge the user's locally-installed agent-browser CLI to their own logged-in Chrome so the CLI can
+automate pages the user is working with, entirely on the user's machine and at the user's command.
+ +

各权限理由 / Permission justifications

+ + + + + + + + + +
权限理由(复制到对应输入框)
debuggerAttaches the Chrome DevTools Protocol to the user's own active tab so the paired local agent-browser CLI can automate it (navigate, click, read DOM) only while the user is running a command. Commands arrive solely from the local CLI via native messaging; there is no remote endpoint.
tabsEnumerate and target the correct open tab to attach automation to.
nativeMessagingThe sole communication channel: a local native-messaging connection to the agent-browser CLI installed on the same machine. No network is used.
storagePersist small local pairing/configuration state for the extension.
alarmsKeep the MV3 service worker alive during longer automation sessions.
webNavigationDetect page loads/navigations so automation can wait for the right moment before acting.
host permissions(若被问)The extension declares none; tab access is mediated through the debugger attach the user initiates.
+ +

数据用途勾选 / Data usage

+
    +
  • 不勾选任何"collects user data"类别。
  • +
  • 三个合规声明全部勾选可以为真:不卖数据 / 不挪作无关用途 / 不用于判断信用资质。
  • +
  • Privacy policy URL:填 privacy.html 的公开地址(见下)。
  • +
+ +

五、隐私政策 URL

+

商店要求一个公开可访问的隐私政策地址。文件已写好:extensions/store/privacy.html。两种托管:

+
    +
  • 推荐 · GitHub Pages(渲染好看):开启后地址类似 https://leeguooooo.github.io/agent-browser-stealth/privacy.html我可以帮你用 gh 开 Pages 并把文件放到位。
  • +
  • 临时 · raw 直链:https://raw.githubusercontent.com/leeguooooo/agent-browser-stealth/main/extensions/store/privacy.html(能访问,但浏览器显示源码不渲染,审核可能不喜欢)。
  • +
+ +

六、截图 / Screenshots(至少 1 张,1280×800 或 640×400)

+

可以截一张 CLI + Chrome 并排的演示图。需要的话我用 cua-driver 截一张合规尺寸的图给你。

+ +

七、提交后

+
    +
  1. 提交审核 → 等几天。审核通过且状态变 Published 后告诉我。
  2. +
  3. 我会把 extension install 的 force-install update_url 切到商店地址并发布新 fork;之后用户 extension install → 批准一次描述文件 → 静默装好(商店扩展不再 [BLOCKED]);或者用户在商店页一键 Add to Chrome
  4. +
+ +
+ 今天的临时可用方案: 在你这台 Mac 上 chrome://extensions → 打开开发者模式 → Load unpacked → 选 extensions/ab-connect,30 秒手动装一次,native messaging + extension connect 立即可用。等商店过审再切静默路径。 +
+ +
agent-browser-stealth · 提交包与文案随扩展版本更新;改扩展后重跑 scripts/pack-extension.sh 并重打 ab-connect.zip
+ + diff --git a/extensions/store/privacy.html b/extensions/store/privacy.html new file mode 100644 index 0000000..70f533a --- /dev/null +++ b/extensions/store/privacy.html @@ -0,0 +1,77 @@ + + + + + +Privacy Policy — agent-browser connect + + + +
+

Privacy Policy — agent-browser connect

+
Chrome extension (id ciiljdlhdpfckdcfkphgmfalanpdejep) · Last updated 2026-06-09
+
+ +

Summary: this extension collects no personal data, contains no analytics or +trackers, and sends nothing to any remote server. It is a local bridge that lets the +user's own agent-browser command-line tool, running on the same computer, drive the +user's logged-in Chrome.

+ +

What the extension does

+

agent-browser connect pairs Chrome with the locally-installed agent-browser CLI over +Chrome native messaging (a local inter-process channel; no network socket, no token). When +the user issues an automation command in the CLI, the extension relays Chrome DevTools Protocol +operations to the tab the user targets. Everything happens on the user's machine, initiated by the +user.

+ +

Data collection & use

+ + + + + + + +
CategoryCollected?Detail
Personally identifiable informationNoNever read, stored, or transmitted.
Browsing historyNoNot collected. Page content is acted on transiently only while the user is running an automation command, and is never stored or sent off-device.
Authentication / cookies / credentialsNoNot read or exported by the extension.
Analytics / telemetryNoThe extension contains no analytics, tracking, or crash-reporting code.
Remote transmissionNoThe extension's only message peer is the local agent-browser CLI via native messaging. It makes no outbound network requests of its own.
+ +

Permissions & why they are needed

+ + + + + + + + +
PermissionPurpose
debuggerAttach the Chrome DevTools Protocol to the user's own tab so the local CLI can automate it, only while the user is actively running a command.
tabsEnumerate and target the correct open tab to automate.
nativeMessagingThe local transport to the paired agent-browser CLI — the extension's sole communication channel.
storagePersist small local pairing/state values.
alarmsKeep the MV3 service worker alive during longer automation sessions.
webNavigationDetect page loads so automation can wait for the right moment.
+ +

Data sharing

+

None. No data is sold, shared, or transferred to third parties. There are no third parties — the +extension talks only to a program the user installed on the same computer.

+ +

Contact

+

Source code, issues, and contact: https://github.com/leeguooooo/agent-browser-stealth

+ +
+ agent-browser connect is open source (Apache-2.0). This policy applies to the extension only. +
+ + diff --git a/extensions/updates.xml b/extensions/updates.xml deleted file mode 100644 index fdc8b88..0000000 --- a/extensions/updates.xml +++ /dev/null @@ -1,13 +0,0 @@ - - - - - - - diff --git a/scripts/pack-extension.sh b/scripts/pack-extension.sh index 10b7bed..3c08abc 100755 --- a/scripts/pack-extension.sh +++ b/scripts/pack-extension.sh @@ -1,34 +1,39 @@ #!/bin/sh -# Re-pack and sign extensions/ab-connect into extensions/ab-connect.crx using the -# stable signing key, then print the extension id. Keeps the crx id (and thus the -# native-messaging allowed_origins + force-install policy) constant across versions. +# Build the Chrome Web Store upload package extensions/ab-connect.zip (and a signed +# extensions/ab-connect.crx for reference) from extensions/ab-connect, keeping the +# extension id constant via the stable signing key + manifest "key". # -# The private key lives at .secrets/ab-connect.pem and is git-ignored. To re-pack -# on another machine / in CI, restore it from a secret first (see RELEASING). +# The id MUST stay ciiljdlhdpfckdcfkphgmfalanpdejep so the native-messaging +# allowed_origins and the force-install policy keep matching. The id is pinned by +# the "key" field in manifest.json (kept in the uploaded zip on purpose). +# +# The private key lives at .secrets/ab-connect.pem and is git-ignored. # # After changing the extension: # 1. bump "version" in extensions/ab-connect/manifest.json -# 2. bump in extensions/updates.xml to match -# 3. run this script -# 4. commit extensions/ab-connect.crx + updates.xml + manifest.json +# 2. run this script +# 3. commit extensions/ab-connect.zip (+ .crx) + manifest.json +# 4. upload ab-connect.zip to the Web Store (see extensions/store/SUBMISSION.html) set -e cd "$(dirname "$0")/.." KEY=.secrets/ab-connect.pem EXT=extensions/ab-connect CHROME="${CHROME_BIN:-/Applications/Google Chrome.app/Contents/MacOS/Google Chrome}" -if [ ! -f "$KEY" ]; then - echo "error: $KEY missing. Restore the signing key (CI secret AB_CONNECT_PEM) before packing." >&2 - exit 1 +# Web Store upload package (zip of the unpacked extension, dotfiles excluded). +rm -f extensions/ab-connect.zip +( cd "$EXT" && zip -rq ../ab-connect.zip . -x '.*' ) +[ -f extensions/ab-connect.zip ] || { echo "error: zip failed" >&2; exit 1; } + +# Signed crx (reference / non-store force-install for managed setups). +if [ -f "$KEY" ]; then + rm -f extensions/ab-connect.crx + "$CHROME" --pack-extension="$PWD/$EXT" --pack-extension-key="$PWD/$KEY" >/dev/null 2>&1 || true + ID=$(openssl rsa -in "$KEY" -pubout -outform DER 2>/dev/null \ + | openssl dgst -sha256 -binary | xxd -p -c256 | head -c32 | tr '0-9a-f' 'a-p') + echo "extension id: $ID" +else + echo "note: $KEY missing — built zip only (no crx)." fi - -rm -f extensions/ab-connect.crx -"$CHROME" --pack-extension="$PWD/$EXT" --pack-extension-key="$PWD/$KEY" >/dev/null 2>&1 || true -[ -f extensions/ab-connect.crx ] || { echo "error: pack failed" >&2; exit 1; } - -ID=$(openssl rsa -in "$KEY" -pubout -outform DER 2>/dev/null \ - | openssl dgst -sha256 -binary | xxd -p -c256 | head -c32 | tr '0-9a-f' 'a-p') -echo "packed extensions/ab-connect.crx" -echo "extension id: $ID" +echo "packed extensions/ab-connect.zip" echo "manifest version: $(grep -o '"version"[^,]*' "$EXT/manifest.json" | head -1)" -echo "updates.xml version: $(grep -o "version='[^']*'" extensions/updates.xml | tail -1)"