0Pricing
Browser Extensions Development (Chrome & Edge) · درس

الأذونات ومطابقة المضيفين

افهم كيفية التصريح بالأذونات اللازمة وطلبها، وكيف تتحكم أذونات المضيفين في الوصول إلى مواقع الويب

الأذونات ومطابقة المضيفين درس مجاني في Browser Extensions Development (Chrome & Edge) على CoddyKit. هذا هو الدرس 3 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Browser Extensions Development (Chrome & Edge)، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Browser Extensions Development (Chrome & Edge) 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Why Extensions Need Permissions

Just like apps on your phone, browser extensions often need special 'permissions' to do their job. These permissions define what your extension can and cannot do.

This system is crucial for user security and privacy. It prevents extensions from accessing information or performing actions they don't need, without your explicit consent.

Two Core Permission Types

In Manifest V3, permissions generally fall into two categories:

  • API Permissions: Access to specific browser features (e.g., managing tabs, saving data).
  • Host Permissions: Access to specific websites (e.g., reading content on example.com).

We'll look at how to declare both in your manifest.json file.

Declaring API Permissions

API permissions are listed under the "permissions" key in your manifest.json. Each string in the array corresponds to a specific browser API.

For example, "storage" lets your extension save user data, and "tabs" allows it to interact with browser tabs (like getting their URLs).

{
  "manifest_version": 3,
  "name": "My Extension",
  "version": "1.0",
  "permissions": [
    "storage",
    "tabs"
  ]
}

The 'activeTab' Permission

The "activeTab" permission is unique. It's an API permission that grants your extension temporary host permissions to the currently active tab.

This access is granted only when the user *invokes* your extension (e.g., clicks its toolbar icon). It's a great way to reduce initial permission warnings, as access is only given when needed.

{
  "manifest_version": 3,
  "name": "ActiveTab Demo",
  "version": "1.0",
  "permissions": [
    "activeTab"
  ]
}

Understanding Host Permissions

Host permissions are crucial for defining which websites your extension can interact with. Without them, your extension cannot read or modify content on web pages.

This is a major security boundary. An extension with host permission for google.com cannot access facebook.com, protecting user data and ensuring privacy.

Specifying Host Permissions

Host permissions are declared in the "host_permissions" array in your manifest.json. You use URL match patterns to specify the domains.

A match pattern like "*://*.example.com/*" means access to all subdomains of example.com over HTTP or HTTPS.

{
  "manifest_version": 3,
  "name": "Host Access",
  "version": "1.0",
  "host_permissions": [
    "*://developer.chrome.com/*",
    "https://www.example.org/*"
  ]
}

Match Pattern Wildcards

Match patterns use special characters:

  • *: Matches any string (except / in scheme/host, or # in path).
  • <all_urls>: A special pattern that matches any URL (http, https, ftp, file). Use this with extreme caution as it grants wide access.

For example, "https://*.google.com/search?*" would match Google search results pages.

Combining API & Host Permissions

Often, your extension will need both API and host permissions. Here's an example for an extension that wants to execute a script on Wikipedia pages.

It needs the "scripting" API permission to run code, and host permission for Wikipedia to define where that code can run.

{
  "manifest_version": 3,
  "name": "Wiki Enhancer",
  "version": "1.0",
  "permissions": [
    "scripting"
  ],
  "host_permissions": [
    "*://*.wikipedia.org/*"
  ]
}

User Consent & Trust

When a user installs your extension, the browser displays a list of all requested permissions. This is their chance to understand what your extension can do.

Always request the minimum necessary permissions. Over-requesting can make users distrust your extension and choose not to install it. Be transparent!

Check Your Understanding

Which statements accurately describe host permissions in Manifest V3 extensions?

Permissions & Host Matching Recap

Great job! You've learned about the vital role of permissions in Manifest V3 extensions.

  • API Permissions: Access browser features (e.g., "storage", "tabs").
  • Host Permissions: Control website access using URL match patterns (e.g., "*://*.google.com/*").
  • "activeTab" is a special API permission that grants temporary host access.
  • Always request the minimum necessary permissions to build user trust.

Understanding these concepts is key to building secure and functional extensions!

الأسئلة الشائعة

هل درس «الأذونات ومطابقة المضيفين» مجاني؟

نعم — نص درس «الأذونات ومطابقة المضيفين» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Browser Extensions Development (Chrome & Edge)، انتقل إلى CoddyKit PRO. تتضمن دورة Browser Extensions Development (Chrome & Edge) 4 دروس في المجموع.

ماذا ستتعلم في «الأذونات ومطابقة المضيفين»؟

افهم كيفية التصريح بالأذونات اللازمة وطلبها، وكيف تتحكم أذونات المضيفين في الوصول إلى مواقع الويب تتمرن على Browser Extensions Development (Chrome & Edge) مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Browser Extensions Development (Chrome & Edge)؟

لا تُشترط خبرة سابقة. Browser Extensions Development (Chrome & Edge) على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 3 من أصل 4.

كم من الوقت يستغرق درس «الأذونات ومطابقة المضيفين»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Browser Extensions Development (Chrome & Edge) هذا؟

نعم. كل درس في Browser Extensions Development (Chrome & Edge) يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. فهم بنية Manifest V3
  2. عمّال الخدمات في الخلفية
  3. الأذونات ومطابقة المضيفين
  4. الإجراء والأيقونات وزر شريط الأدوات
← العودة إلى Browser Extensions Development (Chrome & Edge)