Privacy assesment by AI.
Build LinkLog Development Image / development-image (push) Successful in 28s

This commit is contained in:
Olaf
2026-09-30 09:08:52 +02:00
parent 370a91b23b
commit b89d12769c
3 changed files with 57 additions and 128 deletions
+9 -9
View File
@@ -151,12 +151,6 @@ Run full backend and frontend test suites.
### Assistant outcome
The normal backend suite passed with 46 tests. Frontend and extension validation passed for all JavaScript syntax checks, JSON files, XPI rebuild, and unsigned XPI validation. The warnings-as-errors backend variant failed on unclosed SQLite connection `ResourceWarning` instances under Python 3.13; no functional tests failed.
### User
Validate the Privacy properties of the firefox plugin specifically and report them in Privacy.md
### Assistant outcome
Added `Privacy.md` with a plugin-specific privacy validation covering manifest permissions, active-tab capture scope, local and session storage, outbound network destinations, Firefox `data_collection_permissions`, release validation, and residual privacy risks. Confirmed the signed XPI release metadata validates successfully and identified non-HTTPS backend support as the main remaining privacy caveat.
### User
Address SA-007 and use linklog.example.com as default LINKLOG_PUBLIC_URL.
@@ -285,6 +279,12 @@ Add authenticated admin/user configuration
### Assistant outcome
Added shared bearer-token dependencies, protected user configuration endpoints, restricted plugin administration to administrator accounts, and changed user configuration to use the authenticated user's ID instead of hard-coded `user-1`. The seeded `alice` account is an administrator for development and `bob` remains a standard user. README authentication guidance was added, and the strict backend suite passed with 8 tests.
### User
What are the fingerprinting risks of this system?
### Assistant outcome
Reviewed the public feed, authentication and link APIs, frontend, Firefox extension, Mastodon integration, configuration, and existing security audit. Identified high privacy risk from public link and profile metadata, plus medium risks from deployment/configuration fingerprinting, extension website activity, external-request attribution, and observable authentication behavior. No code changes were made.
### User
Make sure the link-log page is responsive
@@ -1622,10 +1622,10 @@ Implement the same functionality in the firefox plugin
### Assistant outcome
Added the same live character-count warning to the Firefox extension popup: it fetches `/api/public/config` for the limit and the user's `/api/user/plugins/mastodon` post prefix, estimates the assembled Mastodon post length the same way as the New Entry page and backend plugin, and shows a localized `used/limit characters` counter (with an over-limit warning message) that updates on every relevant input and tag toggle. Added the `characterCount`/`characterCountOverLimit` translations to all five locale files (en-US, de, es, fr, nl) and verified all locale JSON files parse and `popup.js` passes a Node syntax check.
# Chat Log
### User
Make those colors less outstanding, this should not stand out. In fact, give the box a title :profile and make it collapsable
Add these findings and recomendations to Privacy.md
### Assistant outcome
Made the feed profile summary use the normal subdued link-item colors and converted it to a native collapsible `<details>` section titled `:profile`. Template and stylesheet diagnostics passed.
# Chat Log
Created `Privacy.md` with a source-grounded privacy and fingerprinting assessment covering public activity correlation, URL and query-parameter leakage, Firefox extension website activity, Mastodon correlation, server-side URL fetching, deployment fingerprinting, authentication observability, user guidance, and prioritized mitigations. Validated the document contents; no runtime code was changed.