Skip to content

feat: support explicitly reviewed browser extensions #14

Description

@AjnasNB

Outcome\n\nAllow operator-supplied unpacked extensions for dedicated persistent Chromium profiles when the host explicitly enables this surface.\n\n## Required boundary\n\n- disabled by default\n- extension paths must be explicit, local, canonical, and allowlisted by the host\n- no automatic extension discovery from daily browser profiles\n- headed persistent context only unless a tested Chromium mode supports it\n- extension identity and digest recorded in evidence\n- Maqam approval can authorize an allowlisted extension use, but cannot add a new path or widen its authority\n\n## Acceptance\n\n- typed configuration and policy fields\n- digest and provenance receipts\n- server host-configuration gate\n- negative path-traversal and unapproved-extension tests\n- security and deployment documentation

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions