Declared visitors card + crawlproof actors extension (CLI 0.5.0) - #342
Merged
Merged
Conversation
… (CLI 0.5.0) Dashboard: the project stats page gets a "Declared visitors" card after the headline tiles: declared humans / agents, contradictions in red, and named actors (only the viewer's own or public ones, via declaredSummary, the same filter the API uses). With nothing declared it is one muted line linking to Settings -> Declared actors. CLI: `crawlproof actors extension <email|id> [--out] [--label]` mints a token and writes an unpacked MV3 extension (lib/tracker/declareExtension) whose single declarativeNetRequest rule sets Crawlproof-Actor on <base>/api/track only, so an agent's browser declares itself without a code change and the sites it visits never see the token. Verified end to end: generated for riotcoder, loaded in Chrome for Testing, the visit counted on the actor. Fix: `actors revoke --token=<id>` collided with the CLI-wide --token (API key override) and was sent as the bearer: 401 "Malformed token". Now --token-id. Broken since 0.4.0. Docs: the extension, how to load it, and the branded-Chrome caveat. @profullstack/crawlproof 0.4.0 -> 0.5.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ThreatCrush Security Scan49 finding(s) HIGH/CRITICAL: 2 | MEDIUM: 32 | LOW: 15
Snippets are redacted; ThreatCrush never prints matched credential material. |
ThreatCrush flagged the regression test's fixture as a hardcoded credential. It never was one; constructing it the way the rest of the suite does keeps the scanner signal clean without a dismissal. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #339 / #341.
Dashboard. The project stats page gets a Declared visitors card after the headline tiles: declared humans and agents (actors, pageviews, events), contradictions in red, and a table of named actors. Names only for the viewer's own actors or public ones, through
declaredSummary(the same filter as the API). With nothing declared it's one muted line linking to Settings → Declared actors. Hidden if the actor tables can't be read.crawlproof actors extension <email|id> [--out] [--label]mints a token and writes an unpacked MV3 extension (lib/tracker/declareExtension.ts). Its single declarativeNetRequest rule setsCrawlproof-Actoron<base>/api/trackonly (left-anchored on the origin), so an agent's browser declares itself with no code change and the sites it visits never see the token. Folder 0700, files 0600, README with load instructions for Chromium, Puppeteer, Playwright and chrome-devtools-mcp.Fix:
actors revoke --token=<id>collided with the CLI-wide--token(API key override), so the token id was sent as the bearer → 401 "Malformed token". It's now--token-id. Broken since 0.4.0.Docs: extension section on /docs/statistics, including the branded-Chrome-137+ caveat.
@profullstack/crawlproof0.4.0 → 0.5.0 (publish after merge).Checks: tsc clean; vitest 218 files / 2753 tests. New: rule scoping, MV3 permissions, self-hosted base, refusal of non-token / non-http base, files written private, regression through the package's real
parseArgs/apiToken. End to end against production: generated the extension for riotcoder with the built CLI, loaded it in Chrome for Testing, opened crawlproof.com → riotcoder's count went 3 → 4 and the token showed as used. Test token revoked with the fixed--token-id.🤖 Generated with Claude Code