For your next side project, make a browser extension
geoffreylitt.com
geoffreylitt.com
[0] https://chrome.google.com/webstore/detail/akndolpagcjaolannk... [1] https://chrome.google.com/webstore/detail/icdbglcdnjonofjpcf...
The way to make the prompt sound less scary, is to use finer-grained permissions where the worst-case thing someone could do is less scary.
(Or, if there aren't any fine-grained permissions suited to doing your task — then propose some! The browser vendors would love to get real feedback on the kinds of fine-grained hypothetical privileges that extensions authors would actually find useful. Otherwise they're stuck reading the source code of a small sample of extensions, and extrapolating general patterns of privilege-use from there.)
I understand that - I wrote just that in my comment above. But it's a lot scarier to see a pop-up saying "This extension in the worst case does this", versus the worst-case scenario and a longer explanation. I see from your profile that you're at a web3 analytics company. I'll just say that I think metamask would be a lot less popular if at install-time, the chrome store alerted that it can "make you lose all your crypto savings". Yes this is possible, but there's more to the situation than just a few words, and you can't express that all in an alert() window.
> if there aren't any fine-grained permissions suited to doing your task — then propose some I think that is easy to say, but being subscribed to and reading updates to the extension feedback threads that I've been on for the last few years, I'm not super confident in Google acting on community feedback.
People rightfully point out that if you have access to current URL, you technically have access to browsing history. The right approach is to assume you will use it, hence the warning. Unfortunately, the only way to prevent this is to ensure the extension never, ever gets to make a networking request on its own, or populates any field that could become part of a network request triggered made by the site, or another extension.
It's a trust issue. It's not just fear that you might theoretically sell your extension to some unscrupulous third party. I don't know you personally. I have no reason to assume you are not an unscrupulous party. At this point there is, like, four or five extensions I trust enough to use, and it's mostly because they're OSS and it would be frontpage news on HN if any of them deviated from the expected functionality even slightly.
Having much finer-grained permission system would help a little, at the cost of making it incomprehensible to most users; there's a limit past which it's too complicated to be useful. We need actual innovation in the trust space - by which I don't mean crypto zero-trust shenanigans, but rather a system in which I can trust that, should the browser extension or phone app turn malicious, the vendor will be legally liable, and that it's actually enforced - thus disincentivizing malicious apps/extensions.
Web3 services like MetaMask are primary examples which should have these big warnings, because crypto is rife with scams where someone does something (e.g. open an AirDrop, save their seed phrase in Google Drive) which gives an attacker access to their account without realizing. I don't doubt MetaMask is legit, but you want people to be diligent and understand that whenever they hook up one of these apps to their wallet they are giving a lot of potential for it to be compromised, so maybe be careful and honestly maybe use less of them.
I think what Google is doing is correct.
"This extension wants be able to inject content in any tab. (Warning: This could potentially be used to track history of sites, and access all browsing data)."
That is actually accurate, while the current message is misleading.
Imagine this sort of scheme extended to "root" permission in ChromeOS. The stating worse case vs accurate with warning about worse case would be as follows:
> [Appname] wants permission to steel all your data and brick your device.
and
> [Appname] wants full control of this device. (Warning: this level of access could be used to steal your data, or brick your device).
The first one is most likely untrue, and borders on libel, while the second is true and accurate.
I'm curious, where are people supposed to do this? Is there actually a space / mechanism for this? Or is this a thing they would "like" to exist that there's not really an avenue for?
We did, related to adblocking, they ignored it
https://developer.chrome.com/docs/extensions/mv3/manifest/ac...
I wouldn't be against an "App Store" model provided users could go around it if they chose. I think Mozilla does something like this with certain "featured" extensions?
A review process can help but sadly it’s got a lot of work to do if it want to actually “solve” the problems here.
I don't know if they still do it now or even if the browser is still developed.
> it feels like a gap in the permissions model.
It _is_ a gap in the permissions model.Try analyze these things while wearing a tinfoil hat. Google wants to gimp extensions so that we're one-step further away from tampering with the precious data pipe that Google wants from their servers to the user's monitor/eyeballs. If it gets in the way of that, they will neglect it (whether purposefully or conveniently unintentionally like these seemingly benign wording).
The APIs would still be grouped by permission, but the user would be able to expand into a list of checkmarks showing to what extent those permissions are used. As well, an alert would be shown if any API usage changes between updates.
1) Bypassing any sort of static analysis of your extension requires, at worst, crafting an arbitrary code execution attack against yourself. This is not particuarly difficult.
2) Often times, the specific method you want to use is more powerful than what you need to do, so even if you were restricted to those specific methods, you still have more power than you actually use.
3) Supposing you want to go down the "whitelist at the method level" approach, you could just ... whitelist at the method level. The developer knows what methods he will be calling, so just have a seperate permission for each of them. In practice, this would lead to a lot of permissions that are effectivly equievelent, and people would be asking why they aren't just bundled together in a single permission.
The example raised elsewhere in the thread is good: in a browser, if you have access to the current URL of any tab in context of which you run, you can start building browsing history. Whatever mitigations one could think of get defeated if the extension is allowed to make network requests, or modify content of web pages. Once an extension can communicate with outside world, it can exfil the data, even if piece by piece - and it can also keep its state outside of the browser.
Same applies to mobile apps.
Browser extensions are severely underrated as a platform because they aren't sexy. For all that mobile devices have given us, so much of our work continues to be done using a desktop browser. Enhancements such as augmenting websites with widgets, supplying contextual information, and automating repetitive tasks using the authenticated session - when applied appropriately - can save someone hours every day.
Nah, it's because it's a niche, fragmented platform on which it's very hard to make real money. It's also a very fragile platform that makes very clear you're a sharecropper who can be evicted on a whim by any browser vendor.
I like extensions, I've built several for personal and public use, but I wouldn't invest a penny on them.
I have built a couple of extensions. It's not fun.
The review process, both on Chrome and on Firefox, is long and incredibly annoying. (For example, including minified versions of popular libraries like Lodash gets you stern warnings... Why can't the review process check automatically, and once and for all, that the library is safe and that the version included in an extension is correct?)
The promise of "build once, run everywhere" runs aground very fast because of slight differences between browsers, and because some bugs on Firefox stay unfixed for years.
Sideloading has been made difficult to the point of impossibility.
And now Manifest V3 sucked all the remaining fun out of it.
It's very clear you're building something on someone else's property; they don't like it, they don't like you, and they'll try to fire you at the flimsiest occasion.
Unfortunately, the UI for initiating them isn’t quite as nice as the desktop, which is a big reason why we haven’t implemented our extension for iOS yet. Once Apple figures out a better install and activation workflow, then we’ll probably do it.
1. download extension
2. open Safari and tap on puzzle piece icon on the left side of the address bar (when visible)
3. tap the newly downloaded extension
4. when prompted, give permission for it to run
5. give permission for it to run always on the current site
6. give permission for it to run on every site
I appreciate the need to secure the user's permission. But this is a super clunky way to do it. This path is especially troublesome for users with disabilities (motor issues, working memory issues, or executive function deficits in particular). And given how much people with disabilities rely on extensions to make browsers/websites accessible, this is not a trivial impact.
I run a startup whose tools are used for accessibility reasons and we have streamlined our product and onboarding in many ways based on feedback from our users with disabilities. The process Apple uses is incredibly cumbersome, and I'm sure that many users with disabilities are lost along the way.
But in the case of the shell apps, it totally makes sense to activate the extension automatically upon installation since that was the whole point of downloading the app/extension.
In the end I switched to the traditional Share Extension.
[0]: https://ktool.io
You must:
1) click kebab menu icon
2) scroll all the way down
3) click ublock icon
4) on another screen click "enter element picker mode"
5) that takes you to the rightmost opened tab (!), so most likely completely different tab than you were using, so you must switch back to your original tab
6) you can finally pick elements
Still, considering that only alternative is Firefox which makes you go to different screen just to switch tab and jump through hoops to be even able to download most extensions, it's still the best Android browser.
Spend too much time on Hacker News? I made an extension to freeze the front page so it updates once every 6 hours.
Spend too much time on Reddit? I made an extension requiring a password to be input for every page I visit.
Want to extensively filter LinkedIn jobs, and track which jobs you've applied to? I made an extension to apply very specific filtering to LinkedIn job postings, and to track my application status.
I do wish the Chrome extension API wasn't so annoying to use. Each time I make an extension I sort of dread the process since it's not a good developer experience, but I always find the result to be very useful in my day-to-day life.
Sounds like the making of a good lifestyle SaaS product.
Me, I just open a guest account, or a new profile, etc. Meaning, the extension is at most a reminder to try to stop. it's still trivial to bypass
Well, of course. You can also disable the extension, but that's not the point.
A bypass for 15 minutes button might be too weak, but a small math problem or a password you need to get from your manager would be enough friction.
The decision to bypass after being interrupted is with you, and that's ok.
They're not that hard to code, but both Google and Mozilla keep making changes and then bitching at you through their app stores to change your thing. I recently dropped Chrome support on an add-on because 90% of the users were on Firefox. Since it blocked some ads, I figured Google would continue to whine, and it wasn't worth the hassle.
On the gripping hand, when the platforms in question are the dominant platforms of, err, all computing in this era, then the above described issue tends to be a minor one, in context, for many applications.
With the manifest v3 update, we're changing our freemium structure, and updating our docs. But since FF hasn't figured out all of their manifest v3 stuff, we're not able to update for that 10% of users. It's going to be confusing because our marketing material will reference the new freemium model. But it's no contest as to what we should primarily reference, since there are so few people on FF by comparison to Chrome.
it's a browser extension that defeats the Pacer monopoly on (many) legal filings.
If you do have Pacer and download something, it automatically uploads it to a free server. Thus, it becomes free to everyone else. I think some Big Law firms must use it, because a surprisingly large number of docs are available free.
Legalities of this? They seem to be getting away with it.
The US government runs PACER itself, they don't contract it to a profit-motivated third-party. [1] As a result, they're pretty lenient. At one point, their website said: "The information gathered from the PACER system is a matter of public record and may be reproduced without permission".
So it's totally legal.
The RECAP people also make it _really_ easy to ingest documents. For example, lawyers can add a RECAP email address as one of their default contact addresses with the court. Then all filings on any case that lawyer is involved in get automatically ingested when they are filed.
[1]: Well, they outsource the administration to a third-party. But it seems more like a "we pay you, you keep the lights on", vs a public-private partnership where the third-party has a profit incentive based on the revenue of the service.
I put in the "legalities" part mainly because I was thinking of a similar extension to defeat Elsevier & other vultures of scientific publication. Those people might be more litigious.
That’s a great way to have your life savings drained, or worse. Don’t do it if you live anywhere where you can be nabbed by Uncle Sam. See Aaron Swartz, Alexandra Elbakyan.
My home province gave a private company a 50+ year monopoly on our land title records. I would _love_ something like RECAP for our land title records...but I suspect it's not possible to do it without violating the usage agreement that gets you the record in the first place.
You have to sign up to the Chrome Web Store Developer Dashboard and agree to all the terms and conditions, semi-publish the extension to a limited group of people (probably only yourself), and AFAIK you need to be logged in as one of the group members in order to be able to then see the webstore page of the extension and install it.
In order to update a small issue you need to submit a new version and wait for approval and hope that your account doesn't get flagged because you're using the extension to store all your (tab-)history into a custom database.
https://chrome.google.com/webstore/detail/tabist/hdjegjggiog...
That was around 5-7 years ago and I haven't checked if there was a new alternative, easier way to do it nowadays. I'm still using my extensions but have no need to modify them. Let's see what Manifest v3 has to tell me about this. I'll probably drop Chrome then.
Firefox requires uploading to Mozilla for signing to side load permanently or host with them. Though you can self host once signed.
IME Firefox add-ons are approved almost instantly if your addon is not minified or downloading code to execute outside the package. Chrome approvals are always days.
Are you sure?
I’ve been sideloading extensions, signed or not, into /usr/lib/firefox/browser/extensions/ and they’ve been working fine.
I’m also maintaining a couple AUR packages with Firefox extensions myself. They all use the same method for persistence. I’m wondering what kind of issues people are experiencing. Haven’t heard of any myself.
[0]: https://aur.archlinux.org/packages/firefox-extension-multi-a...
- either upload it on their website and go through approval everytime
- either lower security to run in developer mode, and have an alert warning you about it every X minutes, ruining your focus
VSCode on the other hand has no issue running local extensions at the same time as extensions from the marketplace.
Also, I don't see how you can compare browser extensions to vscode extensions. One product is aimed at your grandma, the other at software developers and doesn't have access to your email, banking and credit cards.
Someone I interviewed once did something like this and we couldn't think of a reason not to hire them because they effectively showed us they were capable of understanding and modifying our existing code which was basically what we wanted in a candidate.
They’re incredibly easy to make and can create a lot of value, plus they’re shareable.
As an example…I built https://SimplifyRecipe.com/shortcut in a couple hours and it’s been extremely useful for getting rid of the life story on recipe pages. Lots of people connected with that concept, so now I’m working on building a full-fledged app.
It’s a bit of a Wild West right now so there are very few resources. I just started building a couple tools using the shortcuts app (it comes with a builder GUI).
The system is more powerful than it looks. You can pull HTML from pages, grab all the links, do for each loops, if statements, variables, etc.
the biggest drawbacks are (1) the UI in the shortcuts app is targeted at non-developers and (2) not all features are supported on older devices and (3) you can’t issue “updates”, so once you share a shortcut it’s just out there and (4) people don’t usually have context for what a shortcut is.
But in exchange you get instant, one-click install without an approval process. It’s pretty cool!
I hope it works well for her. There’s still lots more work to do to get it fully working but we will get there! Really appreciate it.
The short answer is by being web-first and absurdly fast. SimplifyRecipe is for people who used Pinterest for a couple years but got annoyed by the cruft in that ecosystem.
With Twitter, earning the pixels in the site UI is even more fraught as it's a React Native for Web app, so you really don't want to touch the app's own DOM directly, as it will most likely get wiped out on the next render.
e.g. The latest version of Tweak New Twitter [0] keeps you on the "Following" timeline, gets rids of the new "For you" tab and adds a new "Retweets" tab - to highlight the Retweets tab as active when the user clicks it, I had to add a styling hook class to <body> and use that to manually style the Retweet tab as active and override styles for existing tabs to make them display as inactive. Another layer of fun: at any point the user can change the Default/Dim/Lights out theme and the highlight colour using the Display dialogue, so I needed to figure out how to detect these changes, figure out what was now being used and re-apply them to custom UI on the fly.
[0] https://github.com/insin/tweak-new-twitter#tweak-new-twitter
https://addons.mozilla.org/en-US/firefox/user/14310707/
But it's also worth considering where the browser gives priority. For example, while browser extensions can add custom keyboard shortcuts, they can't override the keybindings a website uses. Want to use the keyboard shortcut Ctrl-Shift-1 for a browser extension while a Google Docs page is focused? Nope, sorry, can't be done.
https://github.com/gsomoza/firefox-easy-container-shortcuts/...
It's pretty clear that while a browser extension can access browser APIs that a web app can't, the extension is still a second-class citizen in other respects.
Often I'm reading a page and I come across some location like a city name or some place around the world or a GPS coordinate. Or something I want to research further. Now I just highlight it then select the appropriate action from the menu that popups up. Through the settings menu you can extend it further and add your own search.
Side note: For web search you can search using whatever search engine you want. Just change the string in the settings menu.
Here's the Firefox version: https://addons.mozilla.org/en-US/firefox/addon/popup-tooltip...
And the Chrome version (yeah had to learn Manifest v3 to port): https://chrome.google.com/webstore/detail/popup-tooltip/opbi...
I use this often and made it for myself... but maybe others find it useful too.
There are plenty of plugins already available, but it's also possible to create your own very easily.
I had a quick Google and it seems there are similar apps available for Windows, but I don't know anything about them.
Also, I run a service that lets extension developers take payments in their extensions and it's been really cool to see many extensions take off like the author describes.
- Remove Floating Banners: A button that gets rid of all `position: fixed` elements on a page to give you more reading room. https://chrome.google.com/webstore/detail/remove-floating-ba...
- Autodelete History by Keywords: Remove history / download entries for keywords or URLs automatically as you browse. https://chrome.google.com/webstore/detail/autodelete-history...
— Auto Scroll Search: Lets you CTRL-f search infinitely scrolling web pages. https://chrome.google.com/webstore/detail/auto-scroll-search...
Link? Edit: nvm, found it https://extensionpay.com/
Firefox MV3 is also a bit different, requiring some swapping / toggling that wasn't needed for MV2.
Worth the pain though as extensions are like magic fairy dust for websites you otherwise cannot control.
1. https://developer.chrome.com/blog/more-mv2-transition/ 2. https://groups.google.com/a/chromium.org/g/chromium-extensio...
So it's awkward until Firefox MV3 is ready.
https://blog.chromium.org/2020/01/moving-forward-from-chrome...
Apparently it is now alive-ish (there seem to be a set of follow up announcements) but was burnt.
Notion Boost - 50k+ users , made 3000$ so far https://github.com/GorvGoyl/Notion-Boost-browser-extension/
ChatGPT Writer - 20k+ users within 3 weeks of launch https://chatgptwriter.ai:
Gimme Summary AI - just launched https://gimmesummary.ai
So this plugin sends the contents of the user’s email to ChatGPT?
I understand that it’s clearly opt-in as the user is installing the plugin, but what the heck?
Is there anything a browser extension can do that Tampermonkey cannot?
It's true that many extensions could "just be" Tampermonkey scripts. I'd guess they ship as standalone extensions due to a combination of: less friction to install, more discoverable, can extend with fancier features later on, and probably just inertia/ignorance from developers unaware of Tampermonkey.
While userscripts can't add items to toolbar or context menus, you can register menu commands [1] which have the added benefit of being able to be added dynamically after examining page contents. This is done using the `GM_registerMenuCommand` api [2].
[0]: https://violentmonkey.github.io/guide/keyboard-shortcuts
[1]: https://imgur.com/a/SWpOoRS
[2]: https://violentmonkey.github.io/api/gm/#gm_registermenucomma...
But yeah I have made a few extensions myself since I spend a lot of time in Chrome. If they go ahead with the anti-adblock I will have to learn Firefox's extension.
Tampermoney is an extension, so it can obviously do the same as others. But how much of this does it make accessible to the user scripts? Can you access the local file system? Other Servers? Can you modify the browser-interface itself? Context menu, toolbars, sidebar, add shortcuts, etc.? Can you save persistent data? And can you do all this at an elaborated level of quality?
Blocking ads, translating web pages, bypassing paywalls, adding features to websites (like the YouTube extension), clearing trackers, I could go on and on.
After all this, I still managed to put up Selaro which is a workplace links organizer: https://getselaro.com
https://blog.mozilla.org/addons/2022/11/17/manifest-v3-signi...
extensions allow you to bypass the same-origin policy, but they dont give you the full power of a server. plus with a server, you can choose any language you want, you aren't locked into JavaScript like you are with an extension.
I think though that if browser extensions broadly became capable of browser UI overhauls like Firefox extensions used to be, I'd be much much more interested. Most of the things I want to change about web browsing are in the browser, not the web, and making those changes by way of extension is far more practical than the nightmare of maintaining a browser fork.
If it's an issue, people's usual approach to solving that problem is to create some mapping of "twitter-sidebar : some XPath selector" on the backend and have their extension query whenever they want to interact with the web page.
They'll have e2e tests to check if their selectors or xpaths still work. If not, they'll figure out what changed and modify the xpath. Some automate this step.
It's tricky because A/B tests are a thing, websites might change based on geographical region, and a bunch of other stuff that leads to users seeing different things in the DOM compared to the e2e test). Logging errors to something like Sentry mitigates some of this, but the complexity is still quite large.
It stems from the fact that frontends only consider humans, not robots. You either need to make your robot super resilient to change (above approach), make your robot act more like a human, have the website consider the robot ("Connect to Wallet", etc), or use the web app's backend API if it exists.
We're experimenting with all four of these approaches this year and seeing which ones are the most valuable to people, so stay tuned for more exciting extension stuff!
That said - with an extension some of your code is about interacting with existing pages. For that, much of the time vanilla JS might be good for compatability, since the page itself is already using X or Y or Z framework.
For the menus, extension page and so on, or complicated UI you want to show on top of a page, you could use React.
[0]: https://github.com/claui/tante-jacky/blob/9c6922dd5184fb3674...
Building for someone else's app/extension store always carries some risk, and therefore operational stress. In addition to the manifest v3 concerns others have raised, there are also the random takedown notices (that arrive with zero notice, and for zero reason). It may be easy to get started building an extension, but it's certainly not without operational risk.
You get a crazy powerful state management model that can allow traditional web pages to feel like SPA (your extension around it at least)
It's a shame manifest v3 absolutely butchers this use case because there's no long term live-state management other than opening an extension tab.
I was powering a fairly large amount of state, to the point we had to diff state changes due to browser message costs. It was difficult to write, but was incredibly powerful.
... which requires I sign a legal document and involve a thirdparty gatekeeper. Chrome is practically the same; I'm not going to ask my users to go mess with their browsers' settings assuming they can even do so (policies).
Life is too short to deal with the nonsense of hostile platforms.
peterhil/spellbook: Spellbook is a bookmark extension for Chrome and Firefox https://github.com/peterhil/spellbook
Now I just need good ways to add and search tags, make offline copies (index.html+PDF), and maybe even search the contents of the pages and I'll be golden.
...and a quick way to get burned out due to churn from incompatible changes (either from websites or browsers) breaking your project.
What you're looking for may be modifying an existing Free Software project you use instead, which is something I wholeheartedly recommend. There's often a high chance that you'll be able to upstream your changes, making it better for everyone and taking ongoing maintenance out of your shoulders - unless you actually want to maintain it as your own, which is also something you're free to do.
Obviously depends on the APIs you want, but a typical extension should be trivial to make compatible and package for both Chrome and Firefox.
Disclaimer: I'm the author and maintainer of the framework.
Essentially what I wanted was to be able to implement a simplified version of the "wget" command. I wanted to be able to invoke the extension on a page and have it save the current page contents to a file, then navigate to each link on the page that doesn't go offsite and save those pages, and so on to a specified depth.
(Why not just use wget itself from my terminal? Because the pages I was interested in have JavaScript that modifies the DOM, and it is that modified DOM I want).
I was able to get it working again for a while with some experimental option settings in the Chromium driver which apparently made it harder for a site to figure out that some sort of browser automation was in use, but maybe a couple months later that broke too.
I found a Chromium driver that was specifically made to not be detectable. That didn't help.
I just gave Puppeteer a try, with Chromium and Firefox, and they both got similar CAPTCHA loops.
With Playwright same thing with Chromium and Webkit. With Firefox, to my surprise, it actually worked. In fact I wasn't even shown the CAPTCHA. The checking for a human passed without requiring interaction.
So...looks like Playwright with Firefox might do the trick, but I'm a bit concerned about how reliable that would be long term.
That's one of the reasons I was thinking about an extension--most people using a site are going to have extensions so they aren't going to be able to use the existence of extensions as a sign that a visitor is a bot.
A lot fewer normal users of a site will be using web testing automation frameworks, and so if the site can detect those it might trigger anti-bot measures. I wonder if Cloudflare not being bothered by Playwright in Firefox is due to something Playwright is specifically doing to be undetectable, or just something Cloudflare hasn't gotten around to acting on yet? (I assume it is nothing Firefox specifically did, because of Firefox getting stuck in the CAPTCHA loop under Puppeteer and Selenium).
I thought that if I had a bookmarklet and invoked it on a page, and the bookmarklet navigated to a different page the running instance of that bookmarklet would go away.
So, yes, if you just naively write a bookmarklet that navigates to a new page with e.g. assignment to window.location and then expect any result other than the next line of code not executing, then you're going to be disappointed. You solve this the same way you'd solve it if you were writing an ordinary Web app--implemented in JS delivered by the server with script elements on your own page. Two stupid easy solutions that immediately come to mind: use XHR/fetch instead of actual page navigation; alternatively, have the bookmarklet open up a ~postage stamp-sized window with window.open that you can use both to output visible diagnostics and to keep the crawler resident (by doing all the work in the diagnostic window's context, which uses window.opener to control the initial tab as its puppet)... etc.
https://datum.alwaysdata.net/static/extension/index.html
It crowdsources tags for hacker news threads. And it also adds contextual and relevant real world data while you browse a HN thread.
It's a companion extension for the website https://datum.alwaysdata.net . I want to grow my tester community.. don't be shy !
You can access the code !
I tweeted about this once a while back[0], it gained some traction but never materialized.
This would save a lot of time trying to find transparent images that turn out to be fake. These types of sites are worse than the "fake" github issue tracker sites.
[0]: https://twitter.com/nickjanetakis/status/1545876124865101826
In addition, one annoying thing is "save image as" seems to only work on image tags, not images that come from CSS. So I think some kind of image tool that handles these kinds of issues, including the "is transparent" would be quite cool.
You can do this with some image editors and a "magic wand" but you typically end up with jagged edges unless the shape is basic or you have specialized tools that can auto-feather them in a natural way.
I think with a bit of code you could check if the image type is png and it hasn't been flattened then overlay a little icon that says it's really transparent when you activate the browser extension.
Although I did just discover an interesting trick[0]. If you goto let's say images.google.com and search for something, you can tell right away if it's transparent or not by selecting the image and dragging it to anywhere on the page. If it shows the checker boxes while dragging then it's not transparent.
My life is complete now.
It was a lot of fun to build this, though dealing with the oddities of Chrome was frustrating at times. Especially when it comes to permission granularity.
[0] - https://chrome.google.com/webstore/detail/mastodon-chirper/l...
1. The review process is unstable and frustrating, sometimes it passes in 10 mins, sometimes it takes over ten days, it's painful if you're releasing some emergent bug fixes. 2. No support for monetization at all, Google Adsense are not allowed in browser extensions, no native payment support in the platform.
Is it as bad as I think?
They don't have to. Extensions declare which sites they want access to in the manifest file. Many extensions and user scripts only get access to specific sites.
Maybe there’s a missing manual somewhere that I just couldn’t find, but it all just seemed pretty annoying/painful. Tooling and debugging experience was really lacking.
EDIT: This is specifically regarding chrome extensions.
https://chrome.google.com/webstore/detail/tap-bpm/gfagkcalol...
https://chrome.google.com/webstore/detail/trending-google-se...
Now use my own sidebar extension.
https://addons.mozilla.org/en-US/firefox/addon/grasshopper-u...
HTTPS://HeadlampTest.com
I'm dreading the switch to V3, I'll have to figure out what I can port over and how to do so :/
Might come in helpful for someone: Https://fetcher.page
Also no mobile seems like a big deal
Build an iOS Safari extension. There is a good rush now
You can also use React/Next.js or another frontend library too if you prefer. I had created an extension a while ago out of pure HTML, CSS, and TypeScript but I found that was quite annoying to add more complex features with lots of state. I switched to Next.js and it's now on par with regular web DX [1].
[0] https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
mozilla now requires "add-on signing" [0]; extensions now have to be "signed" (By mozilla) before you can permanently side-load your own private extension onto regular firefox. they also require you to use 2FA [1] when setting up a firefox.com account (which is required in order for you to upload extensions so they can be signed).
at least with chrome you can just enable 'developer mode' and drag and drop your own extensions and use it right away without having to deal with any of that.
[0] https://blog.mozilla.org/addons/2020/03/10/support-for-exten...
[1] https://blog.mozilla.org/addons/2021/03/11/two-factor-authen...
[0] https://github.com/fanfare/googleimagesrestored/releases
1. Ctrl-shift-a to open add-ons page
2. Click the cog, and select "debug add-ons"
3. Click "load temporary add-on"
4. Select a file in your extension.
5. Done.
This worked for me earlier this week.
Key word from the parent post: "temporary"
Ah missed that; yep, the add-on will remain installed until the browser is restarted. That is a little annoying!
https://github.com/JacksonKearl/FeelingBlue/blob/main/extens...
Eg:
"permission": [ "storage", "https://google.com" ]
I could set up server logs locally, but there’s only so many hours in my life.
Not certain that's this user's issue, but that is another thing to check.
It seems the overall handling of network errors in add-ons has a lot of room for improvement.
It should be noted that chromium allows the network request regardless of the CSP. This is the correct, User-Empowering approach. Firefox’s deference to the Origin to control the code the User is attempting to run is the antithesis of what a User Agent ought to be.
I have an implementation on GitHub for my personal hybrid bookmark-manager / hackernews-reader newtab extension[0]. Its still a wip but i use the website version[1] daily as it doesn’t need to be installed and can still be set as my newtab page (warning as I’ve never opened it on mobile).
[0] https://github.com/fractalhq/nutab [1] https://nutab.vercel.app
I’m excited about the ongoing push towards cross-browser standards in this area; Safari has become way more compatible recently as well.
The library is tiny, under 5 kb.