| 2026-10-01 |

Detect login fields with a scoring classifier instead of heuristics
...
field-detect.js is a pure UMD module: every input becomes a descriptor
(name/id/placeholder/aria-label/label text, visibility state, type,
autocomplete token) scored against multilingual keyword tables with
anti-keywords for traps (search, newsletter, cc, otp and now repeat-
password fields). findLoginTargets pairs one username with one password
per form context, merges confirm-password pairs, and falls back to the
closest preceding input in anonymous SPA forms.
content.js reduces to DOM probing (descriptor building + scan) and the
card/interceptor flow; the manifest loads field-detect.js first.
The module is unit-tested without a browser via tools/test-field-detect.js
(16 plain-node cases over a fake tree) and verified end-to-end in Chromium
on a page mixing russian placeholders, newsletter/search/otp/cc traps and
a confirm-password signup form: three cards, correct pairs, Use fills the
right fields only.
Makefile: the per-file $(SRC) replaces the directory prerequisite (a
stale edit inside src/ never rebuilt the bundles), recipes copy with
cp --parents, and make test runs the node suite.
Co-Authored-By: Claude Code <noreply@anthropic.com>
Eugene Sukhodolskiy
committed
6 hours ago
|

Render the autofill card in a closed Shadow DOM
...
The card used to be injected straight into the page: host-page CSS could
restyle it (or hide/mimic it), page JS could read the card's DOM — leaking
secret titles — and reach its buttons via querySelector on our class names.
Now it lives in a closed shadow root on a bare sized-to-zero host element:
- CSS does not cross the shadow boundary in either direction, so page styles
can no longer repaint the card;
- the page cannot traverse into a closed root (host.shadowRoot is null), so
secret titles and buttons are unreachable from the main world;
- src/content.css is no longer injected into page stylesheets — it is now a
web-accessible resource, fetched once per page and injected as a <style>
inside the shadow root (with a graceful no-styles fallback).
- while restyling the card, bring it onto the gnexus-ui-kit 1.0 palette
(panel #16161e, left accent border, uppercase IBM Plex Mono titles) to
match the rebuilt popup.
Verified end-to-end in real Chromium: isolation probe reports a bare empty
host, null shadowRoot, no card nodes or CSS rules reachable from the page,
no title leak under deliberately hostile page CSS (color:red !important over
all divs); clicking Use fills the form and removes the card.
Co-Authored-By: Claude Code <noreply@anthropic.com>
Eugene Sukhodolskiy
committed
6 hours ago
|
Release extension 0.1.1: kit 1.0 lib, shield logo icons
...
Rebuild both browsers' packages against gnexus-ui-kit 1.0 (make lib
from frontend/node_modules) and swap the generic dots mark for the
shield keyhole logo rasterized from frontend/public/logo.svg
(icon.svg + 16/32/48/128 PNG rsvg-convert). Popup verified in
chromium: settings drawer and secrets list render with no page errors.
Version bumped in extension manifest + Makefile; extensions/manifest.json
points at the 0.1.1 zips with fresh sha256/size (0.1.0 zips removed).
Co-Authored-By: Claude Code <noreply@anthropic.com>
Eugene Sukhodolskiy
committed
7 hours ago
|
Import browser extension source under extensions/extension
...
Move the gnexus-creds-extension sources (Chrome/Firefox MV3) from the
separate sibling repository into extensions/extension/ so builds live
next to the packaged releases this service distributes
(extensions/dist/ + extensions/manifest.json, untouched).
- add a reproducible `make lib` target materializing lib/ from the
frontend's pinned gnexus-ui-kit (gitignored, like before)
- drop the playwright-only package.json/lock; system node+zip suffice
- scoped .gitignore so it cannot shadow tracked extensions/dist zips
- README (main + extension): document the in-repo build and publish flow
Rebuilt zips differ from released ones only in the three lib files
(older kit in the release); extension code itself is byte-identical.
Co-Authored-By: Claude Code <noreply@anthropic.com>
Eugene Sukhodolskiy
committed
7 hours ago
|
| 2026-08-25 |
Refresh extension builds (split Chrome/Firefox)
...
Repackage the Chrome and Firefox builds from the extension repo and
update extensions/manifest.json checksums, sizes, and release date.
Co-Authored-By: Claude <noreply@anthropic.com>
Eugene Sukhodolskiy
committed
on 25 Aug
|
| 2026-08-24 |
Add in-app extension download page
...
Distribute the gnexus-creds browser extension from the service itself.
Package Chrome and Firefox builds into extensions/dist/ with a manifest
describing version, checksums, and sizes; serve them via authenticated
FastAPI endpoints and surface a new Extension tab in the Vue UI with
download cards, SHA-256, and install instructions.
Co-Authored-By: Claude <noreply@anthropic.com>
Eugene Sukhodolskiy
committed
on 24 Aug
|