You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e7e40a7
Browse filesBrowse the repository at this point in the historyBrowse files
* feat(tracker): declared visitors card + `crawlproof actors extension` (CLI 0.5.0)
Dashboard: the project stats page gets a "Declared visitors" card after
the headline tiles: declared humans / agents, contradictions in red, and
named actors (only the viewer's own or public ones, via declaredSummary,
the same filter the API uses). With nothing declared it is one muted line
linking to Settings -> Declared actors.
CLI: `crawlproof actors extension <email|id> [--out] [--label]` mints a
token and writes an unpacked MV3 extension (lib/tracker/declareExtension)
whose single declarativeNetRequest rule sets Crawlproof-Actor on
<base>/api/track only, so an agent's browser declares itself without a
code change and the sites it visits never see the token. Verified end to
end: generated for riotcoder, loaded in Chrome for Testing, the visit
counted on the actor.
Fix: `actors revoke --token=<id>` collided with the CLI-wide --token
(API key override) and was sent as the bearer: 401 "Malformed token".
Now --token-id. Broken since 0.4.0.
Docs: the extension, how to load it, and the branded-Chrome caveat.
@profullstack/crawlproof 0.4.0 -> 0.5.0.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* test: build the fake API key instead of a credential-shaped literal
ThreatCrush flagged the regression test's fixture as a hardcoded
credential. It never was one; constructing it the way the rest of the
suite does keeps the scanner signal clean without a dismissal.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
0 commit comments