postulo-chromium: the browser extension for Chromium-based browsers #17

Closed
opened 2026-09-05 12:29:16 +00:00 by tiagoagueda · 0 comments
Owner

Observation

postulo-chromium - webextension to chromium based browsers

What exists today

The capture API was built for this and has been waiting: POST /api/v1/captures takes url and an optional html, and sending the page source lets Postulo capture a posting only visible to a signed-in reader while skipping the server-side fetch entirely (api/api.py, CaptureIn). The response carries review_url. The wiki page The capture API documents the token flow. docs/PLAN.md lists the extension as "deliberately after v1"; this issue ends that.

Shape

  • Manifest V3. One toolbar button and a keyboard shortcut. Press: collect the current tab's URL and document.documentElement.outerHTML through a content script injected on demand with scripting.executeScript — so no permission on every site, only activeTab — post them to the configured instance, show the result (title, company, "read by") and a link to the review screen.
  • Options page. Instance URL and token, in storage.local, not storage.sync: a token replicated across devices through a Google account is not what anyone expects of it. Test calls GET /api/v1/me.
  • Permissions. activeTab, scripting, storage, and the instance's origin as an optional host permission requested at configuration time (permissions.request({ origins: [...] })), because a manifest cannot list a URL it does not know yet. With the host permission granted, requests from the background are not subject to CORS, so Postulo needs no CORS configuration.
  • Later, with #12 read: a badge on the button when the current URL is already tracked; the application's status in the popup; attaching a document to an application from the page.
  • Distribution. The Chrome Web Store (a developer account, a one-off fee) because it is how most people install anything, plus a zip for developer mode. One build serves Chrome, Edge, Brave, Vivaldi, Opera and Arc.
  • Shared code with #18. The two extensions differ in a few manifest keys and a namespace, nothing more. Proposal: one repository producing two builds with web-ext, and postulo-chromium / postulo-firefox as the two published artefacts. The alternative is two repositories over a shared core; see the open question.
  • Privacy, stated in the listing. The extension sends the page to your server and nowhere else. No analytics, no third-party requests, no permanent host permissions.

Classification

Enhancement. A separate repository; changes nothing in Postulo. Not breaking.

Depends on

Nothing for capture: the API exists and is stable. #12 for the read features.

Open questions

  1. One repository for both browsers (proposal) or two?
  2. Publish on the Chrome Web Store under the project's name, or leave the store to whoever wants to?
  3. "Capture selection": send highlighted text as the description for pages with no JSON-LD and unreadable markup?
## Observation > postulo-chromium - webextension to chromium based browsers ## What exists today The capture API was built for this and has been waiting: `POST /api/v1/captures` takes `url` and an optional `html`, and sending the page source lets Postulo capture a posting only visible to a signed-in reader while skipping the server-side fetch entirely (`api/api.py`, `CaptureIn`). The response carries `review_url`. The wiki page *The capture API* documents the token flow. `docs/PLAN.md` lists the extension as "deliberately after v1"; this issue ends that. ## Shape - **Manifest V3.** One toolbar button and a keyboard shortcut. Press: collect the current tab's URL and `document.documentElement.outerHTML` through a content script injected on demand with `scripting.executeScript` — so no permission on every site, only `activeTab` — post them to the configured instance, show the result (title, company, "read by") and a link to the review screen. - **Options page.** Instance URL and token, in `storage.local`, not `storage.sync`: a token replicated across devices through a Google account is not what anyone expects of it. *Test* calls `GET /api/v1/me`. - **Permissions.** `activeTab`, `scripting`, `storage`, and the instance's origin as an **optional host permission requested at configuration time** (`permissions.request({ origins: [...] })`), because a manifest cannot list a URL it does not know yet. With the host permission granted, requests from the background are not subject to CORS, so Postulo needs no CORS configuration. - **Later, with #12 `read`**: a badge on the button when the current URL is already tracked; the application's status in the popup; attaching a document to an application from the page. - **Distribution.** The Chrome Web Store (a developer account, a one-off fee) because it is how most people install anything, plus a zip for developer mode. One build serves Chrome, Edge, Brave, Vivaldi, Opera and Arc. - **Shared code with #18.** The two extensions differ in a few manifest keys and a namespace, nothing more. Proposal: one repository producing two builds with `web-ext`, and `postulo-chromium` / `postulo-firefox` as the two published artefacts. The alternative is two repositories over a shared core; see the open question. - **Privacy, stated in the listing.** The extension sends the page to *your* server and nowhere else. No analytics, no third-party requests, no permanent host permissions. ## Classification Enhancement. A separate repository; changes nothing in Postulo. Not breaking. ## Depends on Nothing for capture: the API exists and is stable. #12 for the read features. ## Open questions 1. One repository for both browsers (proposal) or two? 2. Publish on the Chrome Web Store under the project's name, or leave the store to whoever wants to? 3. "Capture selection": send highlighted text as the description for pages with no JSON-LD and unreadable markup?
tiagoagueda added this to the 0.2.0 milestone 2026-09-05 12:29:16 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Postulo/postulo#17
No description provided.