Privacy assesment by AI.
Build LinkLog Development Image / development-image (push) Successful in 28s
Build LinkLog Development Image / development-image (push) Successful in 28s
This commit is contained in:
+9
-9
@@ -151,12 +151,6 @@ Run full backend and frontend test suites.
|
||||
### Assistant outcome
|
||||
The normal backend suite passed with 46 tests. Frontend and extension validation passed for all JavaScript syntax checks, JSON files, XPI rebuild, and unsigned XPI validation. The warnings-as-errors backend variant failed on unclosed SQLite connection `ResourceWarning` instances under Python 3.13; no functional tests failed.
|
||||
|
||||
### User
|
||||
Validate the Privacy properties of the firefox plugin specifically and report them in Privacy.md
|
||||
|
||||
### Assistant outcome
|
||||
Added `Privacy.md` with a plugin-specific privacy validation covering manifest permissions, active-tab capture scope, local and session storage, outbound network destinations, Firefox `data_collection_permissions`, release validation, and residual privacy risks. Confirmed the signed XPI release metadata validates successfully and identified non-HTTPS backend support as the main remaining privacy caveat.
|
||||
|
||||
### User
|
||||
Address SA-007 and use linklog.example.com as default LINKLOG_PUBLIC_URL.
|
||||
|
||||
@@ -285,6 +279,12 @@ Add authenticated admin/user configuration
|
||||
### Assistant outcome
|
||||
Added shared bearer-token dependencies, protected user configuration endpoints, restricted plugin administration to administrator accounts, and changed user configuration to use the authenticated user's ID instead of hard-coded `user-1`. The seeded `alice` account is an administrator for development and `bob` remains a standard user. README authentication guidance was added, and the strict backend suite passed with 8 tests.
|
||||
|
||||
### User
|
||||
What are the fingerprinting risks of this system?
|
||||
|
||||
### Assistant outcome
|
||||
Reviewed the public feed, authentication and link APIs, frontend, Firefox extension, Mastodon integration, configuration, and existing security audit. Identified high privacy risk from public link and profile metadata, plus medium risks from deployment/configuration fingerprinting, extension website activity, external-request attribution, and observable authentication behavior. No code changes were made.
|
||||
|
||||
### User
|
||||
Make sure the link-log page is responsive
|
||||
|
||||
@@ -1622,10 +1622,10 @@ Implement the same functionality in the firefox plugin
|
||||
|
||||
### Assistant outcome
|
||||
Added the same live character-count warning to the Firefox extension popup: it fetches `/api/public/config` for the limit and the user's `/api/user/plugins/mastodon` post prefix, estimates the assembled Mastodon post length the same way as the New Entry page and backend plugin, and shows a localized `used/limit characters` counter (with an over-limit warning message) that updates on every relevant input and tag toggle. Added the `characterCount`/`characterCountOverLimit` translations to all five locale files (en-US, de, es, fr, nl) and verified all locale JSON files parse and `popup.js` passes a Node syntax check.
|
||||
# Chat Log
|
||||
|
||||
### User
|
||||
Make those colors less outstanding, this should not stand out. In fact, give the box a title :profile and make it collapsable
|
||||
Add these findings and recomendations to Privacy.md
|
||||
|
||||
### Assistant outcome
|
||||
Made the feed profile summary use the normal subdued link-item colors and converted it to a native collapsible `<details>` section titled `:profile`. Template and stylesheet diagnostics passed.
|
||||
# Chat Log
|
||||
Created `Privacy.md` with a source-grounded privacy and fingerprinting assessment covering public activity correlation, URL and query-parameter leakage, Firefox extension website activity, Mastodon correlation, server-side URL fetching, deployment fingerprinting, authentication observability, user guidance, and prioritized mitigations. Validated the document contents; no runtime code was changed.
|
||||
|
||||
+3
-10
@@ -278,6 +278,7 @@
|
||||
248. Release script fails because the runner's hashlib module has no file_digest attribute.
|
||||
249. The filtering on tags does not work. When I click on the button I cannot select. Remember that any visitor on the site should be able to filter the tag for the link-feed.
|
||||
250. Update VIBE and Changelog
|
||||
251. What are the fingerprinting risks of this system?
|
||||
|
||||
## 2026-08-30
|
||||
|
||||
@@ -298,10 +299,6 @@ Where date format is like: 2026 August 29 - 21:10
|
||||
## 2026-09-05
|
||||
|
||||
254. In firefox the search input field is wider (at 180px) then labe search control (at 135.5px)
|
||||
|
||||
## 2026-09-07
|
||||
|
||||
255. Change bg color and slightly decrease the font for 'html body main.container section.link-item.profile-summary' so that it stands out
|
||||
255. In the toolbar switch the search and tag filter's location
|
||||
|
||||
## 2026-09-06
|
||||
@@ -318,15 +315,11 @@ If the user uses the filters and/or search in the toolbox then those should limi
|
||||
259. Make sure the CHANGELOG reflects all changes since commit 74b2c400c6
|
||||
260. Add a skill to maintain the changelog.md
|
||||
261. In the new-entry form, provide a warning when the total ammount of characters is over LINKLOG_MAX_POST_CHARACTERS=500 (also indicat the number of characters used/500 count). This is to prevent Mastodon posts from failing - so all characters should be counted.
|
||||
|
||||
## 2026-09-15
|
||||
|
||||
262. Validate the Privacy properties of the firefox plugin specifically and report them in Privacy.md
|
||||
262. Implement the same functionality in the firefox plugin
|
||||
|
||||
## 2026-09-07
|
||||
## 2026-09-16
|
||||
|
||||
Make those colors less outstanding, this should not stand out. In fact, give the box a title :profile and make it collapsable
|
||||
263. Add these findings and recomendations to Privacy.md
|
||||
|
||||
## Future entries
|
||||
|
||||
|
||||
Reference in New Issue
Block a user