Presenter runs on logged-in work products and is developed in a public repo. Its security model is short, and each point exists because one of those two facts would otherwise leak something.
- It changes how a page looks, never what it does. Enhancements restyle and relabel; they do not submit forms, call APIs, or read data out of the page. A relabel reads an element's text only to decide whether to replace it.
- Nothing leaves the browser. The extension makes no network requests. Settings — which switches are on — are the only thing stored, in
chrome.storage.local, and they contain no page content. - Least privilege.
activeTab(opening the popup grants it, which is how the popup reads the current tab's URL) andstorage. Content scripts inject only on the sites listed inmanifest.json. - No remotely hosted code, no
eval. Every script ships in the extension; MV3's CSP forbids the alternatives, and lint enforces it. - No secrets in the repo. The manifest
keyis a public key (ADR-0002); no private key, token or credential is ever committed. - No real page content in the repo. Fixtures are synthetic; real saved pages stay in the gitignored
test/fixtures/private/(CONTRIBUTING.md).
- No credentials, tokens, cookies or private keys anywhere in the diff
- Fixtures are hand-written and synthetic — no names, emails, org/project slugs, resource IDs or internal URLs
- Enhancement
title/problem, comments, commit messages and PR text describe the UX only — nothing internal - No new permission or target site without a stated reason
- No network request,
eval,new Functionor remotely loaded script -
console.logoutput carries no page content